Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <1306975538.1019611289843415282.JavaMail.root@zmail01.collab.prod.int.phx2.redhat.com>
Date: Mon, 15 Nov 2010 12:50:15 -0500 (EST)
From: Josh Bressers <bressers@...hat.com>
To: oss-security@...ts.openwall.com
Cc: "Steven M. Christey" <coley@...us.mitre.org>
Subject: Re: CVE request: kernel: perf bug

----- "Eugene Teo" <eugene@...hat.com> wrote:

> Upstream commit dab5855 ("perf_counter: Add mmap event hooks to 
> mprotect()") is fundamentally wrong as mprotect_fixup() can free 'vma'
> 
> due to merging. Fix the problem by moving perf_event_mmap() hook to
> mprotect_fixup(). In certain scenario, a local, unprivileged user could
> use this flaw to trigger a denial of service.
> 
> Upstream commit:
> http://git.kernel.org/linus/63bfd7384b119409685a17d5c58f0b56e5dc03da
> 
> https://bugzilla.redhat.com/show_bug.cgi?id=651671
> 
> PS: I thought I requested a CVE name for this already, but it turns out I
> did not.
> 

Please use CVE-2010-4169.

Thanks.

-- 
    JB

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.