[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <CALQ-SODhbky=pHUK1c6S91OE0H+kBS=7UATSNBud82a-hAunQA@mail.gmail.com>
Date: Mon, 15 May 2017 22:53:50 -0700
From: Steven Pease <spease@...tabletech.com>
To: Willy Tarreau <w@....eu>
Cc: linux-kernel@...r.kernel.org
Subject: Re: CVE-2016-10229 in 4.4.x series
Is there any particular reason that the CVE appears to be filed
against 4.4.60? Or is this just a mistake?
http://www.cvedetails.com/cve/CVE-2016-10229/
- Steven
On Mon, May 15, 2017 at 10:20 PM, Willy Tarreau <w@....eu> wrote:
> On Mon, May 15, 2017 at 06:09:53PM -0700, Steven Pease wrote:
>> Hi,
>>
>> This is my first post - not currently subscribed so please CC me. :) I
>> searched a bit for this question, but couldn't find an answer (Googled
>> '2016-10229 site:lkml.org').
>>
>> Does CVE-2016-10229 affect the newest version of the 4.4.x kernel
>> series (currently 4.4.68) and are there any plans to fix this in the
>> 4.4 kernel series?
>
> This one was fixed by upstream commit 197c949 ("udp: properly support
> MSG_PEEK with truncated buffers"), which was backported in 4.4 as
> commit dfe2042d96 in 4.4.21. So in short, 4.4.68 is safe.
>
> Willy
--
- Steven
Powered by blists - more mailing lists