Overview

Request 237091 accepted

- Delete
patches.fixes/0003-futex-Make-lookup_pi_state-more-robust.patch.
- Delete
patches.fixes/0004-futex-Always-cleanup-owner-tid-in-unlock_pi.patch.
Apply only the ones needed for CVE.
- commit b216559

- futex: Always cleanup owner tid in unlock_pi (bnc#880892
CVE-2014-3153).
- futex: Make lookup_pi_state more robust (bnc#880892
CVE-2014-3153).
- futex: Validate atomic acquisition in futex_lock_pi_atomic()
(bnc#880892 CVE-2014-3153).
- futex: Forbid uaddr == uaddr2 in futex_requeue(...,
requeue_pi=1) (bnc#880892 CVE-2014-3153).
- commit 35e5e36

- vhost: fix total length when packets are too short (bnc#870576
CVE-2014-0077).
- vhost: validate vhost_get_vq_desc return value (bnc#870173
CVE-2014-0055).
- commit 18e0f7a

- ext4: Fix buffer double free in ext4_alloc_branch() (bnc#880599
bnc#876981).
- commit 23974bc

- patches.fixes/firewire-01-net-fix-use-after-free.patch,
patches.fixes/firewire-02-ohci-fix-probe-failure-with-agere-lsi-controllers.patch,
patches.fixes/firewire-03-dont-use-prepare_delayed_work.patch: Add

Request History
Marcus Meissner's avatar

msmeissn created request

- Delete
patches.fixes/0003-futex-Make-lookup_pi_state-more-robust.patch.
- Delete
patches.fixes/0004-futex-Always-cleanup-owner-tid-in-unlock_pi.patch.
Apply only the ones needed for CVE.
- commit b216559

- futex: Always cleanup owner tid in unlock_pi (bnc#880892
CVE-2014-3153).
- futex: Make lookup_pi_state more robust (bnc#880892
CVE-2014-3153).
- futex: Validate atomic acquisition in futex_lock_pi_atomic()
(bnc#880892 CVE-2014-3153).
- futex: Forbid uaddr == uaddr2 in futex_requeue(...,
requeue_pi=1) (bnc#880892 CVE-2014-3153).
- commit 35e5e36

- vhost: fix total length when packets are too short (bnc#870576
CVE-2014-0077).
- vhost: validate vhost_get_vq_desc return value (bnc#870173
CVE-2014-0055).
- commit 18e0f7a

- ext4: Fix buffer double free in ext4_alloc_branch() (bnc#880599
bnc#876981).
- commit 23974bc

- patches.fixes/firewire-01-net-fix-use-after-free.patch,
patches.fixes/firewire-02-ohci-fix-probe-failure-with-agere-lsi-controllers.patch,
patches.fixes/firewire-03-dont-use-prepare_delayed_work.patch: Add


Marcus Meissner's avatar

msmeissn accepted request

ok

openSUSE Build Service is sponsored by