Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 722144 (CVE-2019-20795) - <sys-apps/iproute2-5.1.0: Use-after-free in get_netnsid_from_name (CVE-2019-20795)
Summary: <sys-apps/iproute2-5.1.0: Use-after-free in get_netnsid_from_name (CVE-2019-2...
Status: RESOLVED FIXED
Alias: CVE-2019-20795
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: https://git.kernel.org/pub/scm/networ...
Whiteboard: A3 [glsa+ cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2020-05-10 14:32 UTC by Sam James
Modified: 2020-08-08 04:24 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sam James archtester gentoo-dev Security 2020-05-10 14:32:47 UTC
Description:
"iproute2 before 5.1.0 has a use-after-free in get_netnsid_from_name in ip/ipnetns.c."
Comment 1 Sam James archtester gentoo-dev Security 2020-05-10 17:20:34 UTC
@maintainer(s), please apply patch or cleanup(?)
Comment 2 Larry the Git Cow gentoo-dev 2020-07-30 08:04:57 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=b60d2cb2827bd5705fe11364ad68b5f35e550e03

commit b60d2cb2827bd5705fe11364ad68b5f35e550e03
Author:     John Helmert III <jchelmert3@posteo.net>
AuthorDate: 2020-07-29 06:26:09 +0000
Commit:     Lars Wendler <polynomial-c@gentoo.org>
CommitDate: 2020-07-30 08:04:51 +0000

    sys-apps/iproute2: Security cleanup
    
    Bug: https://bugs.gentoo.org/722144
    Package-Manager: Portage-3.0.1, Repoman-2.3.23
    Signed-off-by: John Helmert III <jchelmert3@posteo.net>
    Signed-off-by: Lars Wendler <polynomial-c@gentoo.org>

 sys-apps/iproute2/Manifest                  |   1 -
 sys-apps/iproute2/iproute2-4.19.0-r1.ebuild | 157 ----------------------------
 2 files changed, 158 deletions(-)
Comment 3 Sam James archtester gentoo-dev Security 2020-08-03 07:00:46 UTC
Thanks.
Comment 4 GLSAMaker/CVETool Bot gentoo-dev 2020-08-08 04:24:52 UTC
This issue was resolved and addressed in
 GLSA 202008-06 at https://security.gentoo.org/glsa/202008-06
by GLSA coordinator Sam James (sam_c).