APPLIED: [CVE-2011-4110] fix panic replacing user keys

Tim Gardner tim.gardner at canonical.com
Tue Dec 6 20:27:05 UTC 2011


On 12/06/2011 09:32 AM, Andy Whitcroft wrote:
> CVE-2011-4110
> 	There is a NULL pointer deref in the user-defined key type whereby
> 	updating a negative key into a fully instantiated key will cause
> 	an oops to occur when the code attempts to free the non-existent
> 	old payload.
>
> Fixes for this have hit oneiric and later via mainline and stable.
> Following this email is a patch for hardy, lucid, lucid/fsl-imx51,
> maverick, maverick/ti-omap4, natty, and natty/ti-omap4.  This is a simple
> backport from the mainline commit.
>
> Proposing for hardy, lucid, lucid/fsl-imx51, maverick, maverick/ti-omap4,
> natty, and natty/ti-omap4.
>
> -apw
>


-- 
Tim Gardner tim.gardner at canonical.com




More information about the kernel-team mailing list