Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <20131119205849.GA4572@dhcp-25-225.brq.redhat.com>
Date: Tue, 19 Nov 2013 21:58:50 +0100
From: Petr Matousek <pmatouse@...hat.com>
To: Moritz Muehlenhoff <jmm@...ian.org>
Cc: oss-security@...ts.openwall.com, Prasad Pandit <ppandit@...hat.com>
Subject: Re: CVE requests for three Linux kernel issues

Hi,

On Tue, Nov 19, 2013 at 09:14:14PM +0100, Moritz Muehlenhoff wrote:
> "x90c" reported four kernel issues on f-d. One already has a CVE ID assigned,
> can you please assign one for the remainders?

we've requested only one CVE to be assigned because the rest are
non-issues. Prasad (CC'ed) can provide reasons why.

> 
> XADV-2013008 Linux Kernel 3.11.7 <= sk_attach_filter Kernel Heap Corruption
>   http://seclists.org/fulldisclosure/2013/Nov/139
> 
> XADV-2013007 Linux Kernel bt8xx Video Driver IOCTL Heap Overflow
>   http://seclists.org/fulldisclosure/2013/Nov/126
> 
> XADV-2013004 Linux Kernel ipvs Kernel Stack Overflow
>   http://seclists.org/fulldisclosure/2013/Nov/77
> -> This was already assigned CVE-2013-4588
> 
> XADV-2013003 Linux Kernel bt8xx Video Driver IOCTL Heap Overflow 
>   http://seclists.org/fulldisclosure/2013/Nov/75
> 
> Cheers,
>         Moritz

Thanks,
-- 
Petr Matousek / Red Hat Security Response Team
PGP: 0xC44977CA 8107 AF16 A416 F9AF 18F3  D874 3E78 6F42 C449 77CA

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.