[CVE-2012-2100] ext4_fill_flex_info DOS panic

Andy Whitcroft apw at canonical.com
Fri Apr 20 08:31:20 UTC 2012


CVE-2012-2100
	An incomplete fix for CVE-2009-4307 allows this issue to be
	exploited on PPC

This CVE claims the issue only affects PPC but actually the patch
description implies it is ok on PPC and affects x86.  Regardless the
issue only affects lucid and later, fixes for this have hit everything
but natty via mainline and stable.  Following this email is a patch for
natty, this is a clean cherrypick from the mainline fix.

Proposing for natty and natty/ti-omap4.

Signed-off-by: Andy Whitcroft <apw at canonical.com>




More information about the kernel-team mailing list