[PATCH 0/1] [CVE-2012-2319] hfsplus: Fix potential buffer overflows

Tim Gardner tim.gardner at canonical.com
Thu May 24 13:21:44 UTC 2012


On 05/23/2012 09:21 PM, Brad Figg wrote:
> Following this cover-letter is a single patch that applies the same CVE
> fix to the xen and openvz sections of the Hardy git tree.
> 
> CVE-2012-2319
> 
> Commit ec81aecb2966 ("hfs: fix a potential buffer overflow") fixed a few
> potential buffer overflows in the hfs filesystem.  But as Timo Warns
> pointed out, these changes also need to be made on the hfsplus
> filesystem as well.
> 
> Greg Kroah-Hartman (1):
>   hfsplus: Fix potential buffer overflows
> 
>  fs/hfsplus/catalog.c |    4 ++++
>  fs/hfsplus/dir.c     |   11 +++++++++++
>  2 files changed, 15 insertions(+)
> 

I'm a bit confused. Is there any reason that this patch shouldn't also
apply to the regular hfsplus files, e.g., as in the attached patch ?

rtg
-- 
Tim Gardner tim.gardner at canonical.com
-------------- next part --------------
A non-text attachment was scrubbed...
Name: 0001-hfsplus-Fix-potential-buffer-overflows.patch
Type: text/x-patch
Size: 6467 bytes
Desc: not available
URL: <https://lists.ubuntu.com/archives/kernel-team/attachments/20120524/256ab3d4/attachment.bin>


More information about the kernel-team mailing list