← Back to team overview

kernel-packages team mailing list archive

[Bug 1091188] Re: CVE-2012-5375

 

This bug was fixed in the package linux-ti-omap4 - 3.5.0-232.48

---------------
linux-ti-omap4 (3.5.0-232.48) quantal; urgency=low

  * Release Tracking Bug
    - LP: #1215276

  [ Paolo Pisati ]

  * SAUCE: fixup between 6288223947 and db7981259
  * rebased on Ubuntu-3.5.0-40.62

  [ Ubuntu: 3.5.0-40.62 ]

  * [Config] KUSER_HELPERS = Y
  * Release Tracking Bug
    - LP: #1215129

  [ Ubuntu: 3.5.0-40.61 ]

  * [Packaging] supply perf with appropriate prefix to ensure use of local
    config
    - LP: #1206200
    - CVE-2013-1060
  * Revert "SAUCE: (no-up) AppArmor: Disable Add PR_{GET,SET}_NO_NEW_PRIVS
    to prevent execve from granting privs"
    - LP: #1202161
  * SAUCE: (no-up) intel_ips: blacklist ASUSTek G60JX laptops
    - LP: #1210848
  * (debian) Abort build on unresolved symbols
    - LP: #1166197
  * [Config] Include rbd and kvm in the virtual inclusion list
    - LP: #1206961
  * ALSA: usb: Parse UAC2 extension unit like for UAC1
    - LP: #1212430
  * Btrfs: fix hash overflow handling
    - LP: #1091187, #1091188
    - CVE-2012-5375
  * [media] media: dmxdev: remove dvb_ringbuffer_flush() on writer side
    - LP: #1214956
  * writeback: Fix periodic writeback after fs mount
    - LP: #1214956
  * nfsd4: fix decoding of compounds across page boundaries
    - LP: #1214956
  * ARM: shmobile: emev2 GIO3 resource fix
    - LP: #1214956
  * uprobes: Fix return value in error handling path
    - LP: #1214956
  * tracing: Fix irqs-off tag display in syscall tracing
    - LP: #1214956
  * [CIFS] use sensible file nlink values if unprovided
    - LP: #1214956
  * ASoC: sglt5000: Fix the default value of CHIP_SSS_CTRL
    - LP: #1214956
  * ASoC: sglt5000: Fix SGTL5000_PLL_FRAC_DIV_MASK
    - LP: #1214956
  * [SCSI] megaraid_sas: fix memory leak if SGL has zero length entries
    - LP: #1214956
  * iscsi-target: Fix tfc_tpg_nacl_auth_cit configfs length overflow
    - LP: #1214956
  * dm mpath: fix ioctl deadlock when no paths
    - LP: #1214956
  * dm verity: fix inability to use a few specific devices sizes
    - LP: #1214956
  * lockd: protect nlm_blocked access in nlmsvc_retry_blocked
    - LP: #1214956
  * ext4: don't show usrquota/grpquota twice in /proc/mounts
    - LP: #1214956
  * perf: Clone child context from parent context pmu
    - LP: #1214956
  * perf: Remove WARN_ON_ONCE() check in __perf_event_enable() for valid
    scenario
    - LP: #1214956
  * perf: Fix perf_lock_task_context() vs RCU
    - LP: #1214956
  * ext4: don't allow ext4_free_blocks() to fail due to ENOMEM
    - LP: #1214956
  * drm/radeon/hdmi: make sure we have an afmt block assigned
    - LP: #1214956
  * ACPI / memhotplug: Fix a stale pointer in error path
    - LP: #1214956
  * PM / Sleep: avoid 'autosleep' in shutdown progress
    - LP: #1214956
  * radeon kms: do not flush uninitialized hotplug work
    - LP: #1214956
  * svcrdma: underflow issue in decode_write_list()
    - LP: #1214956
  * ALSA: asihpi: Fix unlocked snd_pcm_stop() call
    - LP: #1214956
  * ALSA: atiixp: Fix unlocked snd_pcm_stop() call
    - LP: #1214956
  * ALSA: 6fire: Fix unlocked snd_pcm_stop() call
    - LP: #1214956
  * ALSA: ua101: Fix unlocked snd_pcm_stop() call
    - LP: #1214956
  * ALSA: usx2y: Fix unlocked snd_pcm_stop() call
    - LP: #1214956
  * ALSA: pxa2xx: Fix unlocked snd_pcm_stop() call
    - LP: #1214956
  * ASoC: s6000: Fix unlocked snd_pcm_stop() call
    - LP: #1214956
  * [media] saa7134: Fix unlocked snd_pcm_stop() call
    - LP: #1214956
  * staging: line6: Fix unlocked snd_pcm_stop() call
    - LP: #1214956
  * ALSA: hda - Add new GPU codec ID to snd-hda
    - LP: #1214956
  * ALSA: hda - Add new GPU codec ID to snd-hda
    - LP: #1214956
  * Btrfs: fix lock leak when resuming snapshot deletion
    - LP: #1214956
  * xen/blkback: Check device permissions before allowing OP_DISCARD
    - LP: #1214956
  * [SCSI] Fix incorrect memset in bnx2fc_parse_fcp_rsp
    - LP: #1214956
  * MAINTAINERS: add stable_kernel_rules.txt to stable maintainer
    information
    - LP: #1214956
  * bridge: fix switched interval for MLD Query types
    - LP: #1214956
  * ipv4: Fixed MD5 key lookups when adding/ removing MD5 to/ from TCP
    sockets.
    - LP: #1214956
  * ipv6: don't call addrconf_dst_alloc again when enable lo
    - LP: #1214956
  * macvtap: fix recovery from gup errors
    - LP: #1214956
  * ipv6: ip6_sk_dst_check() must not assume ipv6 dst
    - LP: #1214956
  * af_key: fix info leaks in notify messages
    - LP: #1214956
  * sh_eth: fix unhandled RFE interrupt
    - LP: #1214956
  * neighbour: fix a race in neigh_destroy()
    - LP: #1214956
  * x25: Fix broken locking in ioctl error paths.
    - LP: #1214956
  * net: Swap ver and type in pppoe_hdr
    - LP: #1214956
  * ipv6,mcast: always hold idev->lock before mca_lock
    - LP: #1214956
  * l2tp: add missing .owner to struct pppox_proto
    - LP: #1214956
  * ipv6: call udp_push_pending_frames when uncorking a socket with AF_INET
    pending data
    - LP: #1214956
  * ipv6: ip6_append_data_mtu did not care about pmtudisc and frag_size
    - LP: #1214956
  * sunvnet: vnet_port_remove must call unregister_netdev
    - LP: #1214956
  * ifb: fix rcu_sched self-detected stalls
    - LP: #1214956
  * macvtap: correctly linearize skb when zerocopy is used
    - LP: #1214956
  * ipv6: in case of link failure remove route directly instead of letting
    it expire
    - LP: #1214956
  * 9p: fix off by one causing access violations and memory corruption
    - LP: #1214956
  * dummy: fix oops when loading the dummy failed
    - LP: #1214956
  * ifb: fix oops when loading the ifb failed
    - LP: #1214956
  * atl1e: fix dma mapping warnings
    - LP: #1214956
  * atl1e: unmap partially mapped skb on dma error and free skb
    - LP: #1214956
  * vlan: fix a race in egress prio management
    - LP: #1214956
  * sparc32: vm_area_struct access for old Sun SPARCs.
    - LP: #1214956
  * sparc64 address-congruence property
    - LP: #1214956
  * sparc: tsb must be flushed before tlb
    - LP: #1214956
  * powerpc/modules: Module CRC relocation fix causes perf issues
    - LP: #1214956
  * usb: dwc3: gadget: don't prevent gadget from being probed if we fail
    - LP: #1214956
  * usb: dwc3: fix wrong bit mask in dwc3_event_type
    - LP: #1214956
  * ASoC: max98088 - fix element type of the register cache.
    - LP: #1214956
  * ata: Fix DVD not dectected at some platform with Wellsburg PCH
    - LP: #1214956
  * ALSA: usb-audio: 6fire: return correct XRUN indication
    - LP: #1214956
  * usb: serial: cp210x: Add USB ID for Netgear Switches embedded serial
    adapter
    - LP: #1214956
  * USB: storage: Add MicroVault Flash Drive to unusual_devs
    - LP: #1214956
  * USB: misc: Add Manhattan Hi-Speed USB DVI Converter to sisusbvga
    - LP: #1214956
  * USB: option: append Petatel NP10T device to GSM modems list
    - LP: #1214956
  * usb: cp210x support SEL C662 Vendor/Device
    - LP: #1214956
  * USB: cp210x: add MMB and PI ZigBee USB Device Support
    - LP: #1214956
  * USB: EHCI: Fix resume signalling on remote wakeup
    - LP: #1214956
  * drm/radeon: fix endian issues with DP handling (v3)
    - LP: #1214956
  * drm/radeon: Another card with wrong primary dac adj
    - LP: #1214956
  * drm/radeon: improve dac adjust heuristics for legacy pdac
    - LP: #1214956
  * drm/radeon: fix combios tables on older cards
    - LP: #1214956
  * [SCSI] isci: Fix a race condition in the SSP task management path
    - LP: #1214956
  * [SCSI] qla2xxx: Properly set the tagging for commands.
    - LP: #1214956
  * [SCSI] sd: fix crash when UA received on DIF enabled device
    - LP: #1214956
  * nfsd: nfsd_open: when dentry_open returns an error do not propagate as
    struct file
    - LP: #1214956
  * USB: option: add D-Link DWM-152/C1 and DWM-156/C1
    - LP: #1214956
  * staging: comedi: COMEDI_CANCEL ioctl should wake up read/write
    - LP: #1214956
  * staging: android: logger: Correct write offset reset on error
    - LP: #1214956
  * usb: option: add TP-LINK MA260
    - LP: #1214956
  * USB: ti_usb_3410_5052: fix dynamic-id matching
    - LP: #1214956
  * usb: serial: option: Add ONYX 3G device support
    - LP: #1214956
  * md/raid10: remove use-after-free bug.
    - LP: #1214956
  * md/raid5: fix interaction of 'replace' and 'recovery'.
    - LP: #1214956
  * xhci: Avoid NULL pointer deref when host dies.
    - LP: #1214956
  * usb: host: xhci: Enable XHCI_SPURIOUS_SUCCESS for all controllers with
    xhci 1.0
    - LP: #1214956
  * xhci: fix null pointer dereference on ring_doorbell_for_active_rings
    - LP: #1214956
  * usb: serial: option: blacklist ONDA MT689DC QMI interface
    - LP: #1214956
  * usb: serial: option: add Olivetti Olicard 200
    - LP: #1214956
  * usb: serial: option.c: remove ONDA MT825UP product ID fromdriver
    - LP: #1214956
  * USB: mos7840: fix memory leak in open
    - LP: #1214956
  * usb: Clear both buffers when clearing a control transfer TT buffer.
    - LP: #1214956
  * staging: comedi: fix a race between do_cmd_ioctl() and read/write
    - LP: #1214956
  * hrtimers: Move SMP function call to thread context
    - LP: #1214956
  * Linux 3.5.7.18
    - LP: #1214956
  * nl80211: fix mgmt tx status and testmode reporting for netns
    - LP: #1214956
  * mac80211: fix ethtool stats for non-station interfaces
    - LP: #1214956
  * mac80211: fix duplicate retransmission detection
    - LP: #1214956
  * iwlwifi: mvm: refuse connection to APs with BI < 16
    - LP: #1214956
  * ath9k_htc: do some initial hardware configuration
    - LP: #1214956
  * USB: mos7840: fix race in register handling
    - LP: #1214956
  * USB: mos7840: fix device-type detection
    - LP: #1214956
  * serial/mxs-auart: fix race condition in interrupt handler
    - LP: #1214956
  * serial/mxs-auart: increase time to wait for transmitter to become idle
    - LP: #1214956
  * firewire: fix libdc1394/FlyCap2 iso event regression
    - LP: #1214956
  * USB: mos7840: fix pointer casts
    - LP: #1214956
  * ixgbe: Fix Tx Hang issue with lldpad on 82598EB
    - LP: #1214956
  * USB: serial: ftdi_sio: add more RT Systems ftdi devices
    - LP: #1214956
  * drm/radeon/atom: initialize more atom interpretor elements to 0
    - LP: #1214956
  * virtio: support unlocked queue poll
    - LP: #1214956
  * virtio_net: fix race in RX VQ processing
    - LP: #1214956
  * libata: make it clear that sata_inic162x is experimental
    - LP: #1214956
  * xen/io/ring.h: new macro to detect whether there are too many requests
    on the ring
    - LP: #1214956
  * xen/blkback: Check for insane amounts of request on the ring (v6).
    - LP: #1214956
  * Btrfs: re-add root to dead root list if we stop dropping it
    - LP: #1214956
  * xen/evtchn: avoid a deadlock when unbinding an event channel
    - LP: #1214956
  * sched: Fix the broken sched_rr_get_interval()
    - LP: #1214956
  * livelock avoidance in sget()
    - LP: #1214956
  * drm/i915: quirk no PCH_PWM_ENABLE for Dell XPS13 backlight
    - LP: #1162026, #1163720, #1214956
  * ACPI / battery: Fix parsing _BIX return value
    - LP: #1214956
  * ARM: poison the vectors page
    - LP: #1214956
  * ARM: poison memory between kuser helpers
    - LP: #1214956
  * ARM: move vector stubs
    - LP: #1214956
  * ARM: use linker magic for vectors and vector stubs
    - LP: #1214956
  * ARM: update FIQ support for relocation of vectors
    - LP: #1214956
  * ARM: allow kuser helpers to be removed from the vector page
    - LP: #1214956
  * powerpc/windfarm: Fix noisy slots-fan on Xserve (rm31)
    - LP: #1214956
  * iwlwifi: add DELL SKU for 5150 HMC
    - LP: #1214956
  * mwifiex: Add missing endian conversion.
    - LP: #1214956
  * rt2x00: fix stop queue
    - LP: #1214956
  * futex: Take hugepages into account when generating futex_key
    - LP: #1214956
  * ALSA: compress: fix the return value for SNDRV_COMPRESS_VERSION
    - LP: #1214956
  * perf: Fix event group context move
    - LP: #1214956
  * arcnet: cleanup sizeof parameter
    - LP: #1214956
  * sysctl net: Keep tcp_syn_retries inside the boundary
    - LP: #1214956
  * ipv6: take rtnl_lock and mark mrt6 table as freed on namespace cleanup
    - LP: #1214956
  * usbnet: do not pretend to support SG/TSO
    - LP: #1214956
  * af_key: more info leaks in pfkey messages
    - LP: #1214956
  * net_sched: Fix stack info leak in cbq_dump_wrr().
    - LP: #1214956
  * net_sched: info leak in atm_tc_dump_class()
    - LP: #1214956
  * 8139cp: Add dma_mapping_error checking
    - LP: #1214956
  * x86, fpu: correct the asm constraints for fxsave, unbreak mxcsr.daz
    - LP: #1214956
  * tracing: Fix fields of struct trace_iterator that are zeroed by mistake
    - LP: #1214956
  * perf tools: Add anonymous huge page recognition
    - LP: #1214956
  * ext4: make sure group number is bumped after a inode allocation race
    - LP: #1214956
  * virtio: console: fix race with port unplug and open/close
    - LP: #1214956
  * virtio: console: fix race in port_fops_open() and port unplug
    - LP: #1214956
  * virtio: console: clean up port data immediately at time of unplug
    - LP: #1214956
  * virtio: console: fix raising SIGIO after port unplug
    - LP: #1214956
  * virtio: console: return -ENODEV on all read operations after unplug
    - LP: #1214956
  * regmap: Add missing header for !CONFIG_REGMAP stubs
    - LP: #1214956
  * cifs: extend the buffer length enought for sprintf() using
    - LP: #1214956
  * [SCSI] megaraid_sas: megaraid_sas driver init fails in kdump kernel
    - LP: #1214956
  * [SCSI] Don't attempt to send extended INQUIRY command if skip_vpd_pages
    is set
    - LP: #1214956
  * drm/cirrus: Invalidate page tables when pinning a BO
    - LP: #1214956
  * drm/mgag200: Invalidate page tables when pinning a BO
    - LP: #1214956
  * drm/ast: invalidate page tables when pinning a BO
    - LP: #1214956
  * drm/i915: do not disable backlight on vgaswitcheroo switch off
    - LP: #1214956
  * ALSA: usb/6fire: Fix potential NULL pointer dereference in comm.c
    - LP: #1214956
  * ALSA: 6fire: fix DMA issues with URB transfer_buffer usage
    - LP: #1214956
  * drm/radeon: always program the MC on startup
    - LP: #1214956
  * ALSA: usb-audio: do not trust too-big wMaxPacketSize values
    - LP: #1214956
  * hwmon: (adt7470) Fix incorrect return code check
    - LP: #1214956
  * ext4: allow the mount options nodelalloc and data=journal
    - LP: #1214956
  * ext4: fix mount/remount error messages for incompatible mount options
    - LP: #1214956
  * usb: core: don't try to reset_device() a port that got just
    disconnected
    - LP: #1214956
  * debugfs: debugfs_remove_recursive() must not rely on
    list_empty(d_subdirs)
    - LP: #1214956
  * [SCSI] nsp32: use mdelay instead of large udelay constants
    - LP: #1214956
  * zram: allow request end to coincide with disksize
    - LP: #1214956
  * Linux 3.5.7.19
    - LP: #1214956
  * mac80211: add time synchronisation with BSS for assoc
    - LP: #1214956
  * Linux 3.5.7.20
    - LP: #1214956

  [ Ubuntu: 3.5.0-39.60 ]

  * Release Tracking Bug
    - LP: #1211872
  * Revert "veth: avoid a NULL deref in veth_stats_one"
  * Revert "veth: extend device features"
  * Revert "veth: reduce stat overhead"
 -- Paolo Pisati <paolo.pisati@xxxxxxxxxxxxx>   Tue, 27 Aug 2013 17:51:34 +0200

** Changed in: linux-ti-omap4 (Ubuntu Saucy)
       Status: Fix Committed => Fix Released

-- 
You received this bug notification because you are a member of Kernel
Packages, which is subscribed to linux-armadaxp in Ubuntu.
https://bugs.launchpad.net/bugs/1091188

Title:
  CVE-2012-5375

Status in “linux” package in Ubuntu:
  Fix Committed
Status in “linux-armadaxp” package in Ubuntu:
  Invalid
Status in “linux-ec2” package in Ubuntu:
  Invalid
Status in “linux-fsl-imx51” package in Ubuntu:
  Invalid
Status in “linux-lts-backport-maverick” package in Ubuntu:
  Invalid
Status in “linux-lts-backport-natty” package in Ubuntu:
  Invalid
Status in “linux-lts-backport-oneiric” package in Ubuntu:
  Invalid
Status in “linux-lts-quantal” package in Ubuntu:
  Invalid
Status in “linux-lts-raring” package in Ubuntu:
  Invalid
Status in “linux-mvl-dove” package in Ubuntu:
  Invalid
Status in “linux-ti-omap4” package in Ubuntu:
  Fix Released
Status in “linux” source package in Lucid:
  New
Status in “linux-armadaxp” source package in Lucid:
  Invalid
Status in “linux-ec2” source package in Lucid:
  New
Status in “linux-fsl-imx51” source package in Lucid:
  Invalid
Status in “linux-lts-backport-maverick” source package in Lucid:
  Invalid
Status in “linux-lts-backport-natty” source package in Lucid:
  Won't Fix
Status in “linux-lts-backport-oneiric” source package in Lucid:
  Invalid
Status in “linux-lts-quantal” source package in Lucid:
  Invalid
Status in “linux-lts-raring” source package in Lucid:
  Invalid
Status in “linux-mvl-dove” source package in Lucid:
  Invalid
Status in “linux-ti-omap4” source package in Lucid:
  Invalid
Status in “linux” source package in Precise:
  New
Status in “linux-armadaxp” source package in Precise:
  New
Status in “linux-ec2” source package in Precise:
  Invalid
Status in “linux-fsl-imx51” source package in Precise:
  Invalid
Status in “linux-lts-backport-maverick” source package in Precise:
  Invalid
Status in “linux-lts-backport-natty” source package in Precise:
  Invalid
Status in “linux-lts-backport-oneiric” source package in Precise:
  Invalid
Status in “linux-lts-quantal” source package in Precise:
  Fix Released
Status in “linux-lts-raring” source package in Precise:
  Invalid
Status in “linux-mvl-dove” source package in Precise:
  Invalid
Status in “linux-ti-omap4” source package in Precise:
  New
Status in “linux” source package in Quantal:
  Fix Released
Status in “linux-armadaxp” source package in Quantal:
  Fix Released
Status in “linux-ec2” source package in Quantal:
  Invalid
Status in “linux-fsl-imx51” source package in Quantal:
  Invalid
Status in “linux-lts-backport-maverick” source package in Quantal:
  Invalid
Status in “linux-lts-backport-natty” source package in Quantal:
  Invalid
Status in “linux-lts-backport-oneiric” source package in Quantal:
  Invalid
Status in “linux-lts-quantal” source package in Quantal:
  Invalid
Status in “linux-lts-raring” source package in Quantal:
  Invalid
Status in “linux-mvl-dove” source package in Quantal:
  Invalid
Status in “linux-ti-omap4” source package in Quantal:
  Fix Released
Status in “linux” source package in Raring:
  Fix Committed
Status in “linux-armadaxp” source package in Raring:
  Invalid
Status in “linux-ec2” source package in Raring:
  Invalid
Status in “linux-fsl-imx51” source package in Raring:
  Invalid
Status in “linux-lts-backport-maverick” source package in Raring:
  Invalid
Status in “linux-lts-backport-natty” source package in Raring:
  Invalid
Status in “linux-lts-backport-oneiric” source package in Raring:
  Invalid
Status in “linux-lts-quantal” source package in Raring:
  Invalid
Status in “linux-lts-raring” source package in Raring:
  Invalid
Status in “linux-mvl-dove” source package in Raring:
  Invalid
Status in “linux-ti-omap4” source package in Raring:
  Fix Released
Status in “linux” source package in Saucy:
  Fix Committed
Status in “linux-armadaxp” source package in Saucy:
  Invalid
Status in “linux-ec2” source package in Saucy:
  Invalid
Status in “linux-fsl-imx51” source package in Saucy:
  Invalid
Status in “linux-lts-backport-maverick” source package in Saucy:
  Invalid
Status in “linux-lts-backport-natty” source package in Saucy:
  Invalid
Status in “linux-lts-backport-oneiric” source package in Saucy:
  Invalid
Status in “linux-lts-quantal” source package in Saucy:
  Invalid
Status in “linux-lts-raring” source package in Saucy:
  Invalid
Status in “linux-mvl-dove” source package in Saucy:
  Invalid
Status in “linux-ti-omap4” source package in Saucy:
  Fix Released

Bug description:
  The CRC32C feature in the Btrfs implementation in the Linux kernel
  before 3.8-rc1 allows local users to cause a denial of service
  (prevention of file creation) by leveraging the ability to write to a
  directory important to the victim, and creating a file with a crafted
  name that is associated with a specific CRC32C hash value.

  Break-Fix: 39279cc3d2704cfbf9c35dcb5bdd392159ae4625
  9c52057c698fb96f8f07e7a4bcf4801a092bda89

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1091188/+subscriptions