[Hardy] SRU reguest LP#231746

Stefan Bader stefan.bader at canonical.com
Wed Sep 10 21:38:25 UTC 2008


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

https://bugs.launchpad.net/ubuntu/hardy/+source/linux/+bug/231746

SRU justification:

Impact: iov_iter_advance() skips over zero-length iovecs, however it does not
properly terminate at the end of the iovec array. This leads to kernel crashed
under this circumstances.

Fix: Check i->count before skipping zero length iov. And also include a fixup
to check whther already iteraded over the whole array. One fix comes from the
2.6.24.y stable tree, the other from the 2.6.26.y stable tree.

Testcase: see bug report.

- --

When all other means of communication fail, try words!


-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFIyD5QP+TjRTJVqvQRAnvRAKDIthKawzU5qmRFEQKHPqVZf1GhwgCfRhjE
P8gz7Yvsjik48/A0LktnV3I=
=nz9M
-----END PGP SIGNATURE-----
-------------- next part --------------
A non-text attachment was scrubbed...
Name: 0001-iov_iter_advance-fix.patch
Type: text/x-vhdl
Size: 2649 bytes
Desc: not available
URL: <https://lists.ubuntu.com/archives/kernel-team/attachments/20080910/d864e355/attachment.bin>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: 0001-Fix-off-by-one-error-in-iov_iter_advance.patch
Type: text/x-vhdl
Size: 1769 bytes
Desc: not available
URL: <https://lists.ubuntu.com/archives/kernel-team/attachments/20080910/d864e355/attachment-0001.bin>


More information about the kernel-team mailing list