oss-sec mailing list archives

Status of two Linux kernel issues w/o CVE assignments


From: Moritz Muehlenhoff <jmm () debian org>
Date: Thu, 22 Dec 2011 17:44:47 +0100

Hi,
there were a two Linux-related CVE requests/discussions, which 
didn't end up in an assignment:

1: rose: Add length checks to CALL_REQUEST parsing
e0bccd315db0c2f919e7fcf9cb60db21d9986f52 in mainline

It was decided that this should be split, but without a final
resulting CVE assignment:
http://www.openwall.com/lists/oss-security/2011/04/12/1

2: /proc/$PID/{sched,schedstat} information leak
Vasiliy Kulikov of OpenWall posted a demo exploit.
http://openwall.com/lists/oss-security/2011/11/05/3

AFAICS no CVE ID was assigned to this?

Cheers,
        Moritz


Current thread: