[CVE-2011-2905] perf tools: do not look at ./config for configuration

Andy Whitcroft apw at canonical.com
Fri Oct 7 17:55:36 UTC 2011


CVE-2011-2905
	 perf tools: may parse user-controlled configuration file

The fix for this has hit lucid and oneiric via mainline and stable, hardy
does not have perf.  Following this email is a patch for lucid/fsl-imx51,
maverick, maveric/ti-omap4, natty, and natty/ti-omap4.  This is a simple
cherry-pick from mainline.

Proposing for lucid/fsl-imx51, maverick, maveric/ti-omap4, natty, and
natty/ti-omap4.

-apw




More information about the kernel-team mailing list