← Back to team overview

kernel-packages team mailing list archive

[Bug 1283101] Re: CVE-2014-0069: add hardening patch

 

** Description changed:

  This CVE was fixed under 5d81de8e8667da7135d3a32a964087c0faf5483f but
  there is a second fix which will make this much safer going forward
  against other bugs:
  
-     http://article.gmane.org/gmane.linux.kernel.cifs/9402
+     http://article.gmane.org/gmane.linux.kernel.cifs/9402
  
  Makes sense to put this into any release which needs it.
  
- 
- Dummy sha1 until we have the appropriate one
- 
- Break-fix: - 0000000000000000000000000000000000000000
+ # from cifs branch for-next (may change again yet)
+ Break-fix: - a26054d184763969a411e3939fe243516715ff59

** Also affects: linux (Ubuntu Precise)
   Importance: Undecided
       Status: New

** Also affects: linux (Ubuntu Trusty)
   Importance: Undecided
       Status: Triaged

** Also affects: linux (Ubuntu Saucy)
   Importance: Undecided
       Status: New

** Also affects: linux (Ubuntu Lucid)
   Importance: Undecided
       Status: New

** Also affects: linux (Ubuntu Quantal)
   Importance: Undecided
       Status: New

** Also affects: linux-ec2 (Ubuntu)
   Importance: Undecided
       Status: New

** Also affects: linux-ti-omap4 (Ubuntu)
   Importance: Undecided
       Status: New

** Also affects: linux-lts-quantal (Ubuntu)
   Importance: Undecided
       Status: New

** Also affects: linux-lts-raring (Ubuntu)
   Importance: Undecided
       Status: New

** Also affects: linux-lts-saucy (Ubuntu)
   Importance: Undecided
       Status: New

** Also affects: linux-armadaxp (Ubuntu)
   Importance: Undecided
       Status: New

** Changed in: linux-lts-saucy (Ubuntu Trusty)
       Status: New => Invalid

** Changed in: linux-lts-raring (Ubuntu)
       Status: New => Invalid

** Changed in: linux-armadaxp (Ubuntu)
       Status: New => Invalid

** Changed in: linux-armadaxp (Ubuntu Saucy)
       Status: New => Invalid

** Changed in: linux-lts-saucy (Ubuntu Saucy)
       Status: New => Invalid

** Changed in: linux-lts-quantal (Ubuntu Lucid)
       Status: New => Invalid

** Changed in: linux-ti-omap4 (Ubuntu Lucid)
       Status: New => Invalid

** Changed in: linux-lts-saucy (Ubuntu Lucid)
       Status: New => Invalid

** Changed in: linux-lts-saucy (Ubuntu Quantal)
       Status: New => Invalid

** Changed in: linux-ec2 (Ubuntu)
       Status: New => Invalid

** Changed in: linux-ti-omap4 (Ubuntu)
       Status: New => Invalid

** Changed in: linux-lts-raring (Ubuntu Lucid)
       Status: New => Invalid

** Changed in: linux-lts-raring (Ubuntu Saucy)
       Status: New => Invalid

** Changed in: linux-ec2 (Ubuntu Quantal)
       Status: New => Invalid

** Changed in: linux-lts-quantal (Ubuntu Quantal)
       Status: New => Invalid

** Changed in: linux-armadaxp (Ubuntu Lucid)
       Status: New => Invalid

** Changed in: linux-ec2 (Ubuntu Precise)
       Status: New => Invalid

** Changed in: linux-lts-quantal (Ubuntu Saucy)
       Status: New => Invalid

** Changed in: linux-lts-raring (Ubuntu Quantal)
       Status: New => Invalid

** Changed in: linux-lts-quantal (Ubuntu Trusty)
       Status: New => Invalid

** Changed in: linux-ec2 (Ubuntu Saucy)
       Status: New => Invalid

-- 
You received this bug notification because you are a member of Kernel
Packages, which is subscribed to linux in Ubuntu.
https://bugs.launchpad.net/bugs/1283101

Title:
  CVE-2014-0069: add hardening patch

Status in “linux” package in Ubuntu:
  Triaged
Status in “linux-armadaxp” package in Ubuntu:
  Invalid
Status in “linux-ec2” package in Ubuntu:
  Invalid
Status in “linux-lts-quantal” package in Ubuntu:
  Invalid
Status in “linux-lts-raring” package in Ubuntu:
  Invalid
Status in “linux-lts-saucy” package in Ubuntu:
  Invalid
Status in “linux-ti-omap4” package in Ubuntu:
  Invalid
Status in “linux” source package in Lucid:
  New
Status in “linux-armadaxp” source package in Lucid:
  Invalid
Status in “linux-ec2” source package in Lucid:
  New
Status in “linux-lts-quantal” source package in Lucid:
  Invalid
Status in “linux-lts-raring” source package in Lucid:
  Invalid
Status in “linux-lts-saucy” source package in Lucid:
  Invalid
Status in “linux-ti-omap4” source package in Lucid:
  Invalid
Status in “linux” source package in Precise:
  New
Status in “linux-armadaxp” source package in Precise:
  New
Status in “linux-ec2” source package in Precise:
  Invalid
Status in “linux-lts-quantal” source package in Precise:
  New
Status in “linux-lts-raring” source package in Precise:
  New
Status in “linux-lts-saucy” source package in Precise:
  New
Status in “linux-ti-omap4” source package in Precise:
  New
Status in “linux” source package in Quantal:
  New
Status in “linux-armadaxp” source package in Quantal:
  New
Status in “linux-ec2” source package in Quantal:
  Invalid
Status in “linux-lts-quantal” source package in Quantal:
  Invalid
Status in “linux-lts-raring” source package in Quantal:
  Invalid
Status in “linux-lts-saucy” source package in Quantal:
  Invalid
Status in “linux-ti-omap4” source package in Quantal:
  New
Status in “linux” source package in Saucy:
  New
Status in “linux-armadaxp” source package in Saucy:
  Invalid
Status in “linux-ec2” source package in Saucy:
  Invalid
Status in “linux-lts-quantal” source package in Saucy:
  Invalid
Status in “linux-lts-raring” source package in Saucy:
  Invalid
Status in “linux-lts-saucy” source package in Saucy:
  Invalid
Status in “linux-ti-omap4” source package in Saucy:
  New
Status in “linux” source package in Trusty:
  Triaged
Status in “linux-armadaxp” source package in Trusty:
  Invalid
Status in “linux-ec2” source package in Trusty:
  Invalid
Status in “linux-lts-quantal” source package in Trusty:
  Invalid
Status in “linux-lts-raring” source package in Trusty:
  Invalid
Status in “linux-lts-saucy” source package in Trusty:
  Invalid
Status in “linux-ti-omap4” source package in Trusty:
  Invalid

Bug description:
  This CVE was fixed under 5d81de8e8667da7135d3a32a964087c0faf5483f but
  there is a second fix which will make this much safer going forward
  against other bugs:

      http://article.gmane.org/gmane.linux.kernel.cifs/9402

  Makes sense to put this into any release which needs it.

  # from cifs branch for-next (may change again yet)
  Break-fix: - a26054d184763969a411e3939fe243516715ff59

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1283101/+subscriptions


References