oss-sec mailing list archives

Re: CVE request: kernel: tty: release_one_tty() forgets to put pids


From: Eren Türkay <eren () pardus org tr>
Date: Tue, 27 Apr 2010 09:45:39 +0300

On Thu, Apr 15, 2010 at 08:44:53AM +0800, Eugene Teo wrote:
pgrp member in struct tty_struct was converted to struct pid in
commit ab521dc0, so kernels of version v2.6.26-rc1 and above are
affected by this.

FYI. We use v2.6.25.20 in one of our products. As far as I see from
include/linux/tty.h in 2.6.25 archive that pgrp member in tty_struct is already converted
to "struct pid". I haven't checked the older kernel releases but this
issue exists in 2.6.25. It would be very helpful if someone checked
older kernel releases to correctly determine which releases are vulnerable.

Regards,
Eren


Current thread: