lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date:	Sat, 19 Aug 2006 14:13:55 +0000
From:	Willy Tarreau <wtarreau@...a.kernel.org>
To:	linux-kernel@...r.kernel.org
Cc:	mtosatti@...hat.com
Subject: Linux 2.4.33.1

Hi !

As there were a few security fixes pending and 2.4.34-pre1 has not
received enough validation, I've released 2.4.33.1 with the most
important fixes. All those fixes are already in 2.4.34-pre1.

Particularly important ones are :
 - CVE-2006-1528 : local DoS via direct I/O from the sg driver to mmapped I/O space
   fix from Dann Frazier
 - CVE-2006-4093 : possible local DoS on some PPC970.
   fix from Olof Johansson

Hotfix patches for older versions should follow within a short time.

Regards,
Willy

Summary of changes from v2.4.33 to v2.4.33.1
============================================

dann frazier:
      drivers/scsi/sg.c : fix CVE-2006-1528

Jeff Layton:
      2.4 NFS client - update d_cache when server reports ENOENT on an NFS remove

Willy Tarreau:
      [BLKMTD] : missing offset sometimes causes panics
      [PKTGEN] : fix an oops when used with bonding driver (Tien ChenLi)
      export memchr() which is used by smbfs and lp driver.
      powerpc: Clear HID0 attention enable on PPC970 at boot time
      Change VERSION to 2.4.33.1


-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@...r.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ