[PATCH 0/1][OEM-5.6] CVE-2020-35519: x25_bind oob read

Tim Gardner tim.gardner at canonical.com
Thu Apr 8 20:14:45 UTC 2021


Introduced by 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 (v2.6.12)
and a9288525d2aed806c1b8a785c226d4a9e6371650 (v2.6.34)
Fixed by 6ee50c8e262a0f0693dad264c3c99e30e6442a56 (v5.10)

[SRU Justification]

net/x25: prevent a couple of overflows

[Test Plan]
None.

[Where problems could occur]
User input could be erroneously rejected.

[Other Info]
Released in stable kernels:
linux-4.14.y
linux-4.19.y
linux-4.4.y
linux-4.9.y
linux-5.4.y
linux-5.9.y





More information about the kernel-team mailing list