[Secure-testing-commits] r34587 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Sat May 30 04:05:20 UTC 2015


Author: carnil
Date: 2015-05-30 04:05:20 +0000 (Sat, 30 May 2015)
New Revision: 34587

Modified:
   data/CVE/list
Log:
Add more information for linux issue

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2015-05-30 03:54:39 UTC (rev 34586)
+++ data/CVE/list	2015-05-30 04:05:20 UTC (rev 34587)
@@ -17,7 +17,10 @@
 CVE-2015-4127 (Cross-site scripting (XSS) vulnerability in the church_admin plugin ...)
 	TODO: check
 CVE-2015-XXXX [ns: user namespaces panic]
-	- linux <unfixed>
+	- linux <not-affected> (Commit was applied to 4.0.2 as well but fixed in Debian by two subsequent commits)
+	NOTE: Debian both applies "mnt: Fail collect_mounts when applied to unmounted mounts"
+	NOTE: and "fs_pin: Allow for the possibility that m_list or s_list go unused." in
+	NOTE: 4.0.2-1
 	- linux-2.6 <not-affected> (Introduced and fixed in 4.1-rc1 upstream)
 	NOTE: Introduced by: https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=ce07d891a0891d3c0d0c2d73d577490486b809e1 (v4.1-rc1)
 	NOTE: Fixed by: https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=820f9f147dcce2602eefd9b575bbbd9ea14f0953 (v4.1-rc1)




More information about the Secure-testing-commits mailing list