oss-sec mailing list archives

Re: CVE request -- Linux kernel: mm/hotplug: failure in propagating hot-added memory to other nodes


From: Kurt Seifried <kseifried () redhat com>
Date: Sun, 11 Nov 2012 00:19:13 -0700

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On 11/10/2012 02:36 PM, Petr Matousek wrote:
A NULL pointer dereference flaw has been found in the way a new
node's hot-added memory is propagated to other nodes zonelists. An
unprivileged local user can use this flaw to crash the system.

Upstream fix: 
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=08dff7b7d629807dbb1f398c68dd9cd58dd657a1

 References: https://bugzilla.redhat.com/show_bug.cgi?id=875374

Thanks,

Please use CVE-2012-5517 for this issue.

- -- 
Kurt Seifried Red Hat Security Response Team (SRT)
PGP: 0x5E267993 A90B F995 7350 148F 66BF 7554 160D 4553 5E26 7993

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQIcBAEBAgAGBQJQn1FxAAoJEBYNRVNeJnmTWvsQAMrDnTBXuhLY9/6NXDEgTVYE
xt7129w8UB5GFs78XNqualrLydpWL238QVaysv9JzgPmPwi25LNi3UPvcUitqjH8
FfFVuB+RnltlbJGzu1JlIe7N7sMA87V3laAmIdyoUKOYjyfB3kSA5PUzcWGrq1/v
g8ADw4VpmxuLMk8M1tx0xja+lk/LXH9XgOvyS+e1a7gDyCKCG3GWyT+dyikrQ/O1
2R/SVoYVh6cD8qGtb/voaVKK0KVwzNFrdDe2wDe/IcA+pS6PMuMaz0ml2D5wdlMS
5WBSSCD6ZH/nXOub6viCFDW0UDhyvpkgZXt0P2ix0EUyTlPcWFeDwQ/4fq4RCI+j
aY6GXyDsJPE8V1u+khz7KGFyvBm+y6jq2UCirjshQ7rYeovdbd1BeVDrfBy4ReYR
kTM6VAIwz+GRcaRXgUyIYyR/mpqVtsngPlro23CDHBvifI48uF1H+9MaNYXdrVai
9kkcEuOsTs2NzwNgfchuuTgpHkb38zk8RJ49vjFwp8LcNII5fpn9zWuLkb5baRMw
S5yI5NKpaHH1zgQI8hEd7yGUe6i7SNd7nYsCAWltUsrqJykMe8bBdgX5sgyB40VR
o6Mk/Mj8nE+UaMSc83Vb4Q7SAq0cgxDSuNGIulR6e3eLMO3FlUsOAbnB2uMvtfFa
4bPtoBYIQKCvtjCXLqWu
=mPQs
-----END PGP SIGNATURE-----


Current thread: