[Hardy] SRU reguest LP#231746
Stefan Bader
stefan.bader at canonical.com
Wed Sep 10 21:38:25 UTC 2008
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
https://bugs.launchpad.net/ubuntu/hardy/+source/linux/+bug/231746
SRU justification:
Impact: iov_iter_advance() skips over zero-length iovecs, however it does not
properly terminate at the end of the iovec array. This leads to kernel crashed
under this circumstances.
Fix: Check i->count before skipping zero length iov. And also include a fixup
to check whther already iteraded over the whole array. One fix comes from the
2.6.24.y stable tree, the other from the 2.6.26.y stable tree.
Testcase: see bug report.
- --
When all other means of communication fail, try words!
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org
iD8DBQFIyD5QP+TjRTJVqvQRAnvRAKDIthKawzU5qmRFEQKHPqVZf1GhwgCfRhjE
P8gz7Yvsjik48/A0LktnV3I=
=nz9M
-----END PGP SIGNATURE-----
-------------- next part --------------
A non-text attachment was scrubbed...
Name: 0001-iov_iter_advance-fix.patch
Type: text/x-vhdl
Size: 2649 bytes
Desc: not available
URL: <https://lists.ubuntu.com/archives/kernel-team/attachments/20080910/d864e355/attachment.bin>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: 0001-Fix-off-by-one-error-in-iov_iter_advance.patch
Type: text/x-vhdl
Size: 1769 bytes
Desc: not available
URL: <https://lists.ubuntu.com/archives/kernel-team/attachments/20080910/d864e355/attachment-0001.bin>
More information about the kernel-team
mailing list