[Secure-testing-commits] r48246 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Sat Jan 21 07:21:48 UTC 2017


Author: carnil
Date: 2017-01-21 07:21:48 +0000 (Sat, 21 Jan 2017)
New Revision: 48246

Modified:
   data/CVE/list
Log:
Add CVE-2017-5551/linux

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2017-01-21 07:15:49 UTC (rev 48245)
+++ data/CVE/list	2017-01-21 07:21:48 UTC (rev 48246)
@@ -46,6 +46,9 @@
 	NOTE: https://lists.nongnu.org/archive/html/qemu-devel/2017-01/msg00154.html
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1415281
 	NOTE: Fixed by: http://git.qemu.org/?p=qemu.git;a=commit;h=33243031dad02d161225ba99d782616da133f689
+CVE-2017-5551 [sgid bit not cleared on tmpfs]
+	- linux <unfixed>
+	NOTE: Fixed by: https://git.kernel.org/linus/497de07d89c1410d76a15bec2bb41f24a2a89f31 (4.10-rc4)
 CVE-2017-5538
 	NOT-FOR-US: Samsung Exynos
 CVE-2017-5524




More information about the Secure-testing-commits mailing list