[PATCH 0/1] [CVE-2012-2319] hfsplus: Fix potential buffer overflows

Tim Gardner tim.gardner at canonical.com
Thu May 24 13:26:55 UTC 2012


On 05/24/2012 07:21 AM, Tim Gardner wrote:
> On 05/23/2012 09:21 PM, Brad Figg wrote:
>> Following this cover-letter is a single patch that applies the same CVE
>> fix to the xen and openvz sections of the Hardy git tree.
>>
>> CVE-2012-2319
>>
>> Commit ec81aecb2966 ("hfs: fix a potential buffer overflow") fixed a few
>> potential buffer overflows in the hfs filesystem.  But as Timo Warns
>> pointed out, these changes also need to be made on the hfsplus
>> filesystem as well.
>>
>> Greg Kroah-Hartman (1):
>>   hfsplus: Fix potential buffer overflows
>>
>>  fs/hfsplus/catalog.c |    4 ++++
>>  fs/hfsplus/dir.c     |   11 +++++++++++
>>  2 files changed, 15 insertions(+)
>>
> 
> I'm a bit confused. Is there any reason that this patch shouldn't also
> apply to the regular hfsplus files, e.g., as in the attached patch ?
> 
> rtg
> 
> 
> 

Oh, never mind. I didn't see the initial patch because of the way my
email client orders things. However, I went ahead and applied the
combined patch for Hardy. Isn't that preferable to having 2 patches with
identical subject lines ?

rtg
-- 
Tim Gardner tim.gardner at canonical.com




More information about the kernel-team mailing list