lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <20200228114618.GA2918666@kroah.com>
Date:   Fri, 28 Feb 2020 12:46:18 +0100
From:   Greg Kroah-Hartman <gregkh@...uxfoundation.org>
To:     Jiri Slaby <jslaby@...e.cz>
Cc:     linux-kernel@...r.kernel.org, stable@...r.kernel.org,
        syzbot+59997e8d5cbdc486e6f6@...kaller.appspotmail.com
Subject: Re: [PATCH 5.5 027/150] vt: selection, close sel_buffer race

On Fri, Feb 28, 2020 at 07:54:35AM +0100, Jiri Slaby wrote:
> On 27. 02. 20, 14:36, Greg Kroah-Hartman wrote:
> > From: Jiri Slaby <jslaby@...e.cz>
> > 
> > commit 07e6124a1a46b4b5a9b3cacc0c306b50da87abf5 upstream.
> > 
> > syzkaller reported this UAF:
> 
> With this patch, syzkaller reports possible circular locking dependency:
> https://lore.kernel.org/lkml/000000000000be57bf059f8aa7b9@google.com/
> 
> Could you drop the patch from stable until this is resolved?

Good idea, now dropped from 4.19.y, 5.4.y, and 5.5.y, thanks.

greg k-h

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ