|
Message-ID: <s5htwi4ek94.wl-tiwai@suse.de> Date: Wed, 11 May 2016 16:34:31 +0200 From: Takashi Iwai <tiwai@...e.de> To: cve-assign@...re.org Cc: kangjielu@...il.com, oss-security@...ts.openwall.com, csong84@...ech.edu, insu@...ech.edu, taesoo@...ech.edu Subject: Re: CVE Request: alsa: kernel information leak vulnerability in Linux sound/core/timer On Wed, 11 May 2016 16:26:55 +0200, cve-assign@...re.org wrote: > > > https://git.kernel.org/cgit/linux/kernel/git/tiwai/sound.git/commit/?h=for-next&id=cec8f96e49d9be372fdb0c3836dcf31ec71e457e > > ALSA: timer: Fix leak in SNDRV_TIMER_IOCTL_PARAMS > > > > https://git.kernel.org/cgit/linux/kernel/git/tiwai/sound.git/commit/?h=for-next&id=9a47e9cff994f37f7f0dbd9ae23740d0f64f9fe6 > > ALSA: timer: Fix leak in events via snd_timer_user_ccallback > > > > https://git.kernel.org/cgit/linux/kernel/git/tiwai/sound.git/commit/?h=for-next&id=e4ec8cc8039a7063e24204299b462bd1383184a5 > > ALSA: timer: Fix leak in events via snd_timer_user_tinterrupt > > > > Maybe we can fold > > That is not what we are going to do. Because the meaning of > CVE-2016-4569 was already established to be the > http://comments.gmane.org/gmane.linux.kernel/2214250 issue with the > "tread" object, which is only > cec8f96e49d9be372fdb0c3836dcf31ec71e457e, we are keeping that > ID assignment the same. > > Use CVE-2016-4578 for both 9a47e9cff994f37f7f0dbd9ae23740d0f64f9fe6 > and e4ec8cc8039a7063e24204299b462bd1383184a5. Fair enough. (And, at the next time, please put the maintainer into Cc from the beginning. This would have saved lots of time in both sides.) thanks, Takashi
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.