ACK: [PATCH 0/1] [SRU] [focal/linux-oem-5.6] CVE-2020-25669

Guilherme Piccoli gpiccoli at canonical.com
Thu Mar 11 20:58:39 UTC 2021


On Thu, Mar 11, 2021 at 4:49 PM Tim Gardner <tim.gardner at canonical.com> wrote:
>
> [Impact]
> [use-after-free in sunkbd_reinit]
>
> From the Ubuntu security team:
> Bodong Zhao discovered a use-after-free in the Sun keyboard driver
> implementation in the Linux kernel. A local attacker could use this
> to cause a denial of service or possibly execute arbitrary code.
>
> [Test Case]
> none
>
> [Potential regression]
> Patch released in
> linux-4.14.y
> linux-4.19.y
> linux-4.4.y
> linux-4.9.y
> linux-5.4.y
> linux-5.9.y

Thanks Tim, since it's in multiple stable releases, LGTM:

Acked-by: Guilherme G. Piccoli <gpiccoli at canonical.com>



More information about the kernel-team mailing list