[Secure-testing-commits] r29883 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Fri Nov 7 04:57:19 UTC 2014


Author: carnil
Date: 2014-11-07 04:57:19 +0000 (Fri, 07 Nov 2014)
New Revision: 29883

Modified:
   data/CVE/list
Log:
Add CVE-2014-7826/linux

NOTE (For commit reviewers): This issuse seem to not affect older
kernels i.e. 3.2.63 since the problematic code in introduced at least
with upstream commit 85f2b08268c014e290b600ba49fa85530600eaa1
(v3.14-rc1).

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2014-11-07 04:50:01 UTC (rev 29882)
+++ data/CVE/list	2014-11-07 04:57:19 UTC (rev 29883)
@@ -1812,8 +1812,11 @@
 	NOTE: https://fedorahosted.org/freeipa/ticket/4690
 CVE-2014-7827
 	RESERVED
-CVE-2014-7826
+CVE-2014-7826 [Ftrace subsystem supervisor mode code execution]
 	RESERVED
+	- linux <unfixed>
+	- linux-2.6 <removed>
+	NOTE: Fixed by https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=086ba77a6db00ed858ff07451bedee197df868c9 (v3.18-rc3)
 CVE-2014-7825 [Perf subsystem oob read in supervisor mode (local DoS)]
 	RESERVED
 	- linux <unfixed>




More information about the Secure-testing-commits mailing list