[CVE-2011-4132] jbd/jbd2 superblock validation issue

Andy Whitcroft apw at canonical.com
Tue Nov 22 13:50:31 UTC 2011


CVE-2011-4132
	A flaw was found in the way Linux kernel's Journaling Block Device
	(JBD) handled invalid log first block value. An attacker able to
	mount malicious ext3 or ext4 image could use this flaw to crash
	the system.

Fixes for this issue have hit precise via mainline.  Following this email
is a patch for hardy, lucid, lucid/fsl-imx51, maverick, maverick/ti-omap4,
natty, natty/ti-omap4, and oneiric.  This patch is a simple cherry-pick
for all releases.

Proposing for hardy, lucid, lucid/fsl-imx51, maverick, maverick/ti-omap4,
natty, natty/ti-omap4, and oneiric.

-apw




More information about the kernel-team mailing list