Ubuntu

CVE-2012-4565

Reported by Marc Deslauriers on 2012-11-09
258
This bug affects 1 person
Affects Status Importance Assigned to Milestone
linux (Ubuntu)
Medium
Unassigned
Hardy
Medium
Luis Henriques
Lucid
Medium
Luis Henriques
Oneiric
Medium
Luis Henriques
Precise
Medium
Luis Henriques
Quantal
Medium
Luis Henriques
Raring
Medium
Unassigned
linux-armadaxp (Ubuntu)
Medium
Unassigned
Hardy
Medium
Unassigned
Lucid
Medium
Unassigned
Oneiric
Medium
Unassigned
Precise
Medium
Unassigned
Quantal
Medium
Unassigned
Raring
Medium
Unassigned
linux-ec2 (Ubuntu)
Medium
Unassigned
Hardy
Medium
Unassigned
Lucid
Medium
Unassigned
Oneiric
Medium
Unassigned
Precise
Medium
Unassigned
Quantal
Medium
Unassigned
Raring
Medium
Unassigned
linux-fsl-imx51 (Ubuntu)
Medium
Unassigned
Hardy
Medium
Unassigned
Lucid
Medium
Unassigned
Oneiric
Medium
Unassigned
Precise
Medium
Unassigned
Quantal
Medium
Unassigned
Raring
Medium
Unassigned
linux-lts-backport-maverick (Ubuntu)
Medium
Unassigned
Hardy
Medium
Unassigned
Lucid
Medium
Unassigned
Oneiric
Medium
Unassigned
Precise
Medium
Unassigned
Quantal
Medium
Unassigned
Raring
Medium
Unassigned
linux-lts-backport-natty (Ubuntu)
Undecided
Unassigned
Hardy
Undecided
Unassigned
Lucid
Undecided
Unassigned
Oneiric
Undecided
Unassigned
Precise
Undecided
Unassigned
Quantal
Undecided
Unassigned
Raring
Undecided
Unassigned
linux-lts-backport-oneiric (Ubuntu)
Medium
Unassigned
Hardy
Medium
Unassigned
Lucid
Medium
Unassigned
Oneiric
Medium
Unassigned
Precise
Medium
Unassigned
Quantal
Medium
Unassigned
Raring
Medium
Unassigned
linux-lts-quantal (Ubuntu)
Medium
Unassigned
Hardy
Medium
Unassigned
Lucid
Medium
Unassigned
Oneiric
Medium
Unassigned
Precise
Medium
Unassigned
Quantal
Medium
Unassigned
Raring
Medium
Unassigned
linux-mvl-dove (Ubuntu)
Medium
Unassigned
Hardy
Medium
Unassigned
Lucid
Medium
Unassigned
Oneiric
Medium
Unassigned
Precise
Medium
Unassigned
Quantal
Medium
Unassigned
Raring
Medium
Unassigned
linux-ti-omap4 (Ubuntu)
Medium
Unassigned
Hardy
Medium
Unassigned
Lucid
Medium
Unassigned
Oneiric
Medium
Unassigned
Precise
Medium
Unassigned
Quantal
Medium
Unassigned
Raring
Medium
Unassigned

Bug Description

The tcp_illinois_info function in net/ipv4/tcp_illinois.c in the Linux kernel before 3.4.19, when the net.ipv4.tcp_congestion_control illinois setting is enabled, allows local users to cause a denial of service (divide-by-zero error and OOPS) by reading TCP stats.

Break-Fix: - 8f363b77ee4fbf7c3bbcf5ec2c5ca482d396d664

Marc Deslauriers (mdeslaur) wrote :

CVE-2012-4565

tags: added: kernel-cve-tracking-bug
information type: Public → Public Security
Changed in linux-armadaxp (Ubuntu Oneiric):
status: New → Invalid
Changed in linux-armadaxp (Ubuntu Lucid):
status: New → Invalid
Changed in linux-armadaxp (Ubuntu Hardy):
status: New → Invalid
Changed in linux-ec2 (Ubuntu Precise):
status: New → Invalid
Changed in linux-ec2 (Ubuntu Oneiric):
status: New → Invalid
Changed in linux-ec2 (Ubuntu Raring):
status: New → Invalid
Changed in linux-ec2 (Ubuntu Hardy):
status: New → Invalid
Changed in linux-ec2 (Ubuntu Quantal):
status: New → Invalid
Changed in linux-lts-backport-oneiric (Ubuntu Precise):
status: New → Invalid
Changed in linux-lts-backport-oneiric (Ubuntu Oneiric):
status: New → Invalid
Changed in linux-lts-backport-oneiric (Ubuntu Raring):
status: New → Invalid
Changed in linux-lts-backport-oneiric (Ubuntu Hardy):
status: New → Invalid
Changed in linux-lts-backport-oneiric (Ubuntu Quantal):
status: New → Invalid
Changed in linux-lts-quantal (Ubuntu Precise):
status: New → Invalid
Changed in linux-lts-quantal (Ubuntu Oneiric):
status: New → Invalid
Changed in linux-lts-quantal (Ubuntu Lucid):
status: New → Invalid
Changed in linux-lts-quantal (Ubuntu Raring):
status: New → Invalid
Changed in linux-lts-quantal (Ubuntu Hardy):
status: New → Invalid
Changed in linux-lts-quantal (Ubuntu Quantal):
status: New → Invalid
Changed in linux-mvl-dove (Ubuntu Precise):
status: New → Invalid
Changed in linux-mvl-dove (Ubuntu Oneiric):
status: New → Invalid
Changed in linux-mvl-dove (Ubuntu Raring):
status: New → Invalid
Changed in linux-mvl-dove (Ubuntu Hardy):
status: New → Invalid
Changed in linux-mvl-dove (Ubuntu Quantal):
status: New → Invalid
Changed in linux-lts-backport-maverick (Ubuntu Precise):
status: New → Invalid
Changed in linux-lts-backport-maverick (Ubuntu Oneiric):
status: New → Invalid
Changed in linux-lts-backport-maverick (Ubuntu Raring):
status: New → Invalid
Changed in linux-lts-backport-maverick (Ubuntu Hardy):
status: New → Invalid
Changed in linux-lts-backport-maverick (Ubuntu Quantal):
status: New → Invalid
Changed in linux-ti-omap4 (Ubuntu Lucid):
status: New → Invalid
Changed in linux-ti-omap4 (Ubuntu Hardy):
status: New → Invalid
Changed in linux-fsl-imx51 (Ubuntu Precise):
status: New → Invalid
Changed in linux-fsl-imx51 (Ubuntu Oneiric):
status: New → Invalid
Changed in linux-fsl-imx51 (Ubuntu Raring):
status: New → Invalid
Changed in linux-fsl-imx51 (Ubuntu Hardy):
status: New → Invalid
Changed in linux-fsl-imx51 (Ubuntu Quantal):
status: New → Invalid
description: updated
Changed in linux-armadaxp (Ubuntu Precise):
importance: Undecided → Medium
Changed in linux-armadaxp (Ubuntu Oneiric):
importance: Undecided → Medium
Changed in linux-armadaxp (Ubuntu Lucid):
importance: Undecided → Medium
Changed in linux-armadaxp (Ubuntu Raring):
importance: Undecided → Medium
Changed in linux-armadaxp (Ubuntu Hardy):
importance: Undecided → Medium
Changed in linux-armadaxp (Ubuntu Quantal):
importance: Undecided → Medium
Changed in linux-ec2 (Ubuntu Precise):
importance: Undecided → Medium
Changed in linux-ec2 (Ubuntu Oneiric):
importance: Undecided → Medium
Changed in linux-ec2 (Ubuntu Lucid):
importance: Undecided → Medium
Changed in linux-ec2 (Ubuntu Raring):
importance: Undecided → Medium
Changed in linux-ec2 (Ubuntu Hardy):
importance: Undecided → Medium
Changed in linux-ec2 (Ubuntu Quantal):
importance: Undecided → Medium
Changed in linux-lts-backport-oneiric (Ubuntu Precise):
importance: Undecided → Medium
Changed in linux-lts-backport-oneiric (Ubuntu Oneiric):
importance: Undecided → Medium
Changed in linux-lts-backport-oneiric (Ubuntu Lucid):
importance: Undecided → Medium
Changed in linux-lts-backport-oneiric (Ubuntu Raring):
importance: Undecided → Medium
Changed in linux-lts-backport-oneiric (Ubuntu Hardy):
importance: Undecided → Medium
Changed in linux-lts-backport-oneiric (Ubuntu Quantal):
importance: Undecided → Medium
Changed in linux-lts-quantal (Ubuntu Precise):
importance: Undecided → Medium
Changed in linux-lts-quantal (Ubuntu Oneiric):
importance: Undecided → Medium
Changed in linux-lts-quantal (Ubuntu Lucid):
importance: Undecided → Medium
Changed in linux-lts-quantal (Ubuntu Raring):
importance: Undecided → Medium
Changed in linux-lts-quantal (Ubuntu Hardy):
importance: Undecided → Medium
Changed in linux-lts-quantal (Ubuntu Quantal):
importance: Undecided → Medium
Changed in linux-mvl-dove (Ubuntu Precise):
importance: Undecided → Medium
Changed in linux-mvl-dove (Ubuntu Oneiric):
importance: Undecided → Medium
Changed in linux-mvl-dove (Ubuntu Lucid):
status: New → Invalid
importance: Undecided → Medium
Changed in linux-mvl-dove (Ubuntu Raring):
importance: Undecided → Medium
Changed in linux-mvl-dove (Ubuntu Hardy):
importance: Undecided → Medium
Changed in linux-mvl-dove (Ubuntu Quantal):
importance: Undecided → Medium
Changed in linux-lts-backport-maverick (Ubuntu Precise):
importance: Undecided → Medium
Changed in linux-lts-backport-maverick (Ubuntu Oneiric):
importance: Undecided → Medium
Changed in linux-lts-backport-maverick (Ubuntu Lucid):
status: New → Invalid
importance: Undecided → Medium
Changed in linux-lts-backport-maverick (Ubuntu Raring):
importance: Undecided → Medium
Changed in linux-lts-backport-maverick (Ubuntu Hardy):
importance: Undecided → Medium
Changed in linux-lts-backport-maverick (Ubuntu Quantal):
importance: Undecided → Medium
Changed in linux (Ubuntu Precise):
importance: Undecided → Medium
Changed in linux (Ubuntu Oneiric):
importance: Undecided → Medium
Changed in linux (Ubuntu Lucid):
importance: Undecided → Medium
Changed in linux (Ubuntu Raring):
importance: Undecided → Medium
Changed in linux (Ubuntu Hardy):
importance: Undecided → Medium
Changed in linux (Ubuntu Quantal):
importance: Undecided → Medium
Changed in linux-ti-omap4 (Ubuntu Precise):
importance: Undecided → Medium
Changed in linux-ti-omap4 (Ubuntu Oneiric):
importance: Undecided → Medium
Changed in linux-ti-omap4 (Ubuntu Lucid):
importance: Undecided → Medium
Changed in linux-ti-omap4 (Ubuntu Raring):
importance: Undecided → Medium
Changed in linux-ti-omap4 (Ubuntu Hardy):
importance: Undecided → Medium
Changed in linux-ti-omap4 (Ubuntu Quantal):
importance: Undecided → Medium
Changed in linux-fsl-imx51 (Ubuntu Precise):
importance: Undecided → Medium
Changed in linux-fsl-imx51 (Ubuntu Oneiric):
importance: Undecided → Medium
Changed in linux-fsl-imx51 (Ubuntu Lucid):
status: New → Invalid
importance: Undecided → Medium
Changed in linux-fsl-imx51 (Ubuntu Raring):
importance: Undecided → Medium
Changed in linux-fsl-imx51 (Ubuntu Hardy):
importance: Undecided → Medium
Changed in linux-fsl-imx51 (Ubuntu Quantal):
importance: Undecided → Medium
Luis Henriques (henrix) on 2012-11-12
Changed in linux (Ubuntu Quantal):
assignee: nobody → Luis Henriques (henrix)
status: New → In Progress
Changed in linux (Ubuntu Precise):
assignee: nobody → Luis Henriques (henrix)
status: New → In Progress
Changed in linux (Ubuntu Oneiric):
assignee: nobody → Luis Henriques (henrix)
status: New → In Progress
Changed in linux (Ubuntu Lucid):
assignee: nobody → Luis Henriques (henrix)
status: New → In Progress
Changed in linux (Ubuntu Hardy):
assignee: nobody → Luis Henriques (henrix)
status: New → In Progress
Changed in linux-armadaxp (Ubuntu Precise):
status: New → Fix Committed
Changed in linux-armadaxp (Ubuntu Quantal):
status: New → Fix Committed
Changed in linux-ec2 (Ubuntu Lucid):
status: New → Fix Committed
Changed in linux-lts-backport-oneiric (Ubuntu Lucid):
status: New → Fix Committed
Changed in linux (Ubuntu Precise):
status: In Progress → Fix Committed
Changed in linux (Ubuntu Oneiric):
status: In Progress → Fix Committed
Changed in linux (Ubuntu Lucid):
status: In Progress → Fix Committed
Changed in linux (Ubuntu Raring):
status: New → Invalid
Changed in linux (Ubuntu Hardy):
status: In Progress → Fix Committed
Changed in linux (Ubuntu Quantal):
status: In Progress → Fix Committed
Changed in linux-ti-omap4 (Ubuntu Precise):
status: New → Fix Committed
Changed in linux-ti-omap4 (Ubuntu Oneiric):
status: New → Fix Committed
Changed in linux-ti-omap4 (Ubuntu Quantal):
status: New → Fix Committed
Changed in linux-armadaxp (Ubuntu Raring):
status: New → Fix Committed
Changed in linux-ti-omap4 (Ubuntu Raring):
status: New → Fix Committed
Changed in linux-lts-quantal (Ubuntu Precise):
status: Invalid → Fix Committed
Launchpad Janitor (janitor) wrote :
Download full text (15.1 KiB)

This bug was fixed in the package linux-lts-backport-oneiric - 3.0.0-28.45~lucid1

---------------
linux-lts-backport-oneiric (3.0.0-28.45~lucid1) lucid-proposed; urgency=low

  [Luis Henriques]

  * Release Tracking Bug
    - LP: #1079256

  [ Tim Gardner ]

  * [Config] updateconfigs for stable updates

  [ Upstream Kernel Changes ]

  * Revert "SUNRPC: Ensure we close the socket on EPIPE errors too..."
    - LP: #1075332
  * mn10300: only add -mmem-funcs to KBUILD_CFLAGS if gcc supports it
    - LP: #1067857
  * kbuild: make: fix if_changed when command contains backslashes
    - LP: #1067857
  * media: rc: ite-cir: Initialise ite_dev::rdev earlier
    - LP: #1067857
  * ACPI: run _OSC after ACPI_FULL_INITIALIZATION
    - LP: #1067857
  * PCI: acpiphp: check whether _ADR evaluation succeeded
    - LP: #1067857
  * lib/gcd.c: prevent possible div by 0
    - LP: #1067857
  * kernel/sys.c: call disable_nonboot_cpus() in kernel_restart()
    - LP: #1067857
  * drivers/scsi/atp870u.c: fix bad use of udelay
    - LP: #1067857
  * workqueue: add missing smp_wmb() in process_one_work()
    - LP: #1067857
  * xfrm: Workaround incompatibility of ESN and async crypto
    - LP: #1067857
  * xfrm_user: return error pointer instead of NULL
    - LP: #1067857
  * xfrm_user: return error pointer instead of NULL #2
    - LP: #1067857
  * xfrm: fix a read lock imbalance in make_blackhole
    - LP: #1067857
  * xfrm_user: fix info leak in copy_to_user_auth()
    - LP: #1067857
  * xfrm_user: fix info leak in copy_to_user_state()
    - LP: #1067857
  * xfrm_user: fix info leak in copy_to_user_policy()
    - LP: #1067857
  * xfrm_user: fix info leak in copy_to_user_tmpl()
    - LP: #1067857
  * xfrm_user: don't copy esn replay window twice for new states
    - LP: #1067857
  * xfrm_user: ensure user supplied esn replay window is valid
    - LP: #1067857
  * net: ethernet: davinci_cpdma: decrease the desc count when cleaning up
    the remaining packets
    - LP: #1067857
  * ixp4xx_hss: fix build failure due to missing linux/module.h inclusion
    - LP: #1067857
  * netxen: check for root bus in netxen_mask_aer_correctable
    - LP: #1067857
  * net-sched: sch_cbq: avoid infinite loop
    - LP: #1067857
  * pkt_sched: fix virtual-start-time update in QFQ
    - LP: #1067857
  * sierra_net: Endianess bug fix.
    - LP: #1067857
  * 8021q: fix mac_len recomputation in vlan_untag()
    - LP: #1067857
  * ipv6: release reference of ip6_null_entry's dst entry in __ip6_del_rt
    - LP: #1067857
  * tcp: flush DMA queue before sk_wait_data if rcv_wnd is zero
    - LP: #1067857
  * sctp: Don't charge for data in sndbuf again when transmitting packet
    - LP: #1067857
  * pppoe: drop PPPOX_ZOMBIEs in pppoe_release
    - LP: #1067857
  * net: small bug on rxhash calculation
    - LP: #1067857
  * net: guard tcp_set_keepalive() to tcp sockets
    - LP: #1067857
  * ipv4: raw: fix icmp_filter()
    - LP: #1067857
  * ipv6: raw: fix icmpv6_filter()
    - LP: #1067857
  * ipv6: mip6: fix mip6_mh_filter()
    - LP: #1067857
  * l2tp: fix a typo in l2tp_eth_dev_recv()
    - LP: #1067857
  * netrom: copy_datagram_iovec can fail
    - LP: #1067857
  * net: do not disable sg for...

Changed in linux-lts-backport-oneiric (Ubuntu Lucid):
status: Fix Committed → Fix Released

The verification of this Stable Release Update has completed successfully and the package has now been released to -updates. Subsequently, the Ubuntu Stable Release Updates Team is being unsubscribed and will not receive messages about this bug report. In the event that you encounter a regression using the package from -updates please report a new bug using ubuntu-bug and tag the bug report regression-update so we can easily find any regresssions.

Launchpad Janitor (janitor) wrote :
Download full text (15.0 KiB)

This bug was fixed in the package linux - 3.0.0-28.45

---------------
linux (3.0.0-28.45) oneiric-proposed; urgency=low

  [Luis Henriques]

  * Release Tracking Bug
    - LP: #1078663

  [ Tim Gardner ]

  * [Config] updateconfigs for stable updates

  [ Upstream Kernel Changes ]

  * Revert "SUNRPC: Ensure we close the socket on EPIPE errors too..."
    - LP: #1075332
  * mn10300: only add -mmem-funcs to KBUILD_CFLAGS if gcc supports it
    - LP: #1067857
  * kbuild: make: fix if_changed when command contains backslashes
    - LP: #1067857
  * media: rc: ite-cir: Initialise ite_dev::rdev earlier
    - LP: #1067857
  * ACPI: run _OSC after ACPI_FULL_INITIALIZATION
    - LP: #1067857
  * PCI: acpiphp: check whether _ADR evaluation succeeded
    - LP: #1067857
  * lib/gcd.c: prevent possible div by 0
    - LP: #1067857
  * kernel/sys.c: call disable_nonboot_cpus() in kernel_restart()
    - LP: #1067857
  * drivers/scsi/atp870u.c: fix bad use of udelay
    - LP: #1067857
  * workqueue: add missing smp_wmb() in process_one_work()
    - LP: #1067857
  * xfrm: Workaround incompatibility of ESN and async crypto
    - LP: #1067857
  * xfrm_user: return error pointer instead of NULL
    - LP: #1067857
  * xfrm_user: return error pointer instead of NULL #2
    - LP: #1067857
  * xfrm: fix a read lock imbalance in make_blackhole
    - LP: #1067857
  * xfrm_user: fix info leak in copy_to_user_auth()
    - LP: #1067857
  * xfrm_user: fix info leak in copy_to_user_state()
    - LP: #1067857
  * xfrm_user: fix info leak in copy_to_user_policy()
    - LP: #1067857
  * xfrm_user: fix info leak in copy_to_user_tmpl()
    - LP: #1067857
  * xfrm_user: don't copy esn replay window twice for new states
    - LP: #1067857
  * xfrm_user: ensure user supplied esn replay window is valid
    - LP: #1067857
  * net: ethernet: davinci_cpdma: decrease the desc count when cleaning up
    the remaining packets
    - LP: #1067857
  * ixp4xx_hss: fix build failure due to missing linux/module.h inclusion
    - LP: #1067857
  * netxen: check for root bus in netxen_mask_aer_correctable
    - LP: #1067857
  * net-sched: sch_cbq: avoid infinite loop
    - LP: #1067857
  * pkt_sched: fix virtual-start-time update in QFQ
    - LP: #1067857
  * sierra_net: Endianess bug fix.
    - LP: #1067857
  * 8021q: fix mac_len recomputation in vlan_untag()
    - LP: #1067857
  * ipv6: release reference of ip6_null_entry's dst entry in __ip6_del_rt
    - LP: #1067857
  * tcp: flush DMA queue before sk_wait_data if rcv_wnd is zero
    - LP: #1067857
  * sctp: Don't charge for data in sndbuf again when transmitting packet
    - LP: #1067857
  * pppoe: drop PPPOX_ZOMBIEs in pppoe_release
    - LP: #1067857
  * net: small bug on rxhash calculation
    - LP: #1067857
  * net: guard tcp_set_keepalive() to tcp sockets
    - LP: #1067857
  * ipv4: raw: fix icmp_filter()
    - LP: #1067857
  * ipv6: raw: fix icmpv6_filter()
    - LP: #1067857
  * ipv6: mip6: fix mip6_mh_filter()
    - LP: #1067857
  * l2tp: fix a typo in l2tp_eth_dev_recv()
    - LP: #1067857
  * netrom: copy_datagram_iovec can fail
    - LP: #1067857
  * net: do not disable sg for packets requiring no checksum
    - LP: #1067857
  * ...

Changed in linux (Ubuntu Oneiric):
status: Fix Committed → Fix Released
Launchpad Janitor (janitor) wrote :
Download full text (15.1 KiB)

This bug was fixed in the package linux-ti-omap4 - 3.0.0-1218.31

---------------
linux-ti-omap4 (3.0.0-1218.31) oneiric-proposed; urgency=low

  * Release Tracking Bug
    - LP: #1079255

  [ Paolo Pisati ]

  * rebased on Ubuntu-3.0.0-2.45

  [ Ubuntu: 3.0.0-28.45 ]

  * Release Tracking Bug
    - LP: #1078663
  * [Config] updateconfigs for stable updates
  * Revert "SUNRPC: Ensure we close the socket on EPIPE errors too..."
    - LP: #1075332
  * mn10300: only add -mmem-funcs to KBUILD_CFLAGS if gcc supports it
    - LP: #1067857
  * kbuild: make: fix if_changed when command contains backslashes
    - LP: #1067857
  * media: rc: ite-cir: Initialise ite_dev::rdev earlier
    - LP: #1067857
  * ACPI: run _OSC after ACPI_FULL_INITIALIZATION
    - LP: #1067857
  * PCI: acpiphp: check whether _ADR evaluation succeeded
    - LP: #1067857
  * lib/gcd.c: prevent possible div by 0
    - LP: #1067857
  * kernel/sys.c: call disable_nonboot_cpus() in kernel_restart()
    - LP: #1067857
  * drivers/scsi/atp870u.c: fix bad use of udelay
    - LP: #1067857
  * workqueue: add missing smp_wmb() in process_one_work()
    - LP: #1067857
  * xfrm: Workaround incompatibility of ESN and async crypto
    - LP: #1067857
  * xfrm_user: return error pointer instead of NULL
    - LP: #1067857
  * xfrm_user: return error pointer instead of NULL #2
    - LP: #1067857
  * xfrm: fix a read lock imbalance in make_blackhole
    - LP: #1067857
  * xfrm_user: fix info leak in copy_to_user_auth()
    - LP: #1067857
  * xfrm_user: fix info leak in copy_to_user_state()
    - LP: #1067857
  * xfrm_user: fix info leak in copy_to_user_policy()
    - LP: #1067857
  * xfrm_user: fix info leak in copy_to_user_tmpl()
    - LP: #1067857
  * xfrm_user: don't copy esn replay window twice for new states
    - LP: #1067857
  * xfrm_user: ensure user supplied esn replay window is valid
    - LP: #1067857
  * net: ethernet: davinci_cpdma: decrease the desc count when cleaning up
    the remaining packets
    - LP: #1067857
  * ixp4xx_hss: fix build failure due to missing linux/module.h inclusion
    - LP: #1067857
  * netxen: check for root bus in netxen_mask_aer_correctable
    - LP: #1067857
  * net-sched: sch_cbq: avoid infinite loop
    - LP: #1067857
  * pkt_sched: fix virtual-start-time update in QFQ
    - LP: #1067857
  * sierra_net: Endianess bug fix.
    - LP: #1067857
  * 8021q: fix mac_len recomputation in vlan_untag()
    - LP: #1067857
  * ipv6: release reference of ip6_null_entry's dst entry in __ip6_del_rt
    - LP: #1067857
  * tcp: flush DMA queue before sk_wait_data if rcv_wnd is zero
    - LP: #1067857
  * sctp: Don't charge for data in sndbuf again when transmitting packet
    - LP: #1067857
  * pppoe: drop PPPOX_ZOMBIEs in pppoe_release
    - LP: #1067857
  * net: small bug on rxhash calculation
    - LP: #1067857
  * net: guard tcp_set_keepalive() to tcp sockets
    - LP: #1067857
  * ipv4: raw: fix icmp_filter()
    - LP: #1067857
  * ipv6: raw: fix icmpv6_filter()
    - LP: #1067857
  * ipv6: mip6: fix mip6_mh_filter()
    - LP: #1067857
  * l2tp: fix a typo in l2tp_eth_dev_recv()
    - LP: #1067857
  * netrom: copy_datagram_iovec can fail
    - LP: #1067857
  * net:...

Changed in linux-ti-omap4 (Ubuntu Oneiric):
status: Fix Committed → Fix Released
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package linux - 2.6.24-32.106

---------------
linux (2.6.24-32.106) hardy-proposed; urgency=low

  [Luis Henriques]

  * Release Tracking Bug
    - LP: #1077976

  [Upstream Kernel Changes]

  * net: fix divide by zero in tcp algorithm illinois
    - LP: #1077091
    - CVE-2012-4565
 -- Luis Henriques <email address hidden> Mon, 12 Nov 2012 18:06:22 +0000

Changed in linux (Ubuntu Hardy):
status: Fix Committed → Fix Released
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package linux - 2.6.32-45.100

---------------
linux (2.6.32-45.100) lucid-proposed; urgency=low

  [Luis Henriques]

  * Release Tracking Bug
    - LP: #1078385

  [ Upstream Kernel Changes ]

  * eCryptfs: check for eCryptfs cipher support at mount
    - LP: #338914
  * net: fix divide by zero in tcp algorithm illinois
    - LP: #1077091
    - CVE-2012-4565
 -- Luis Henriques <email address hidden> Tue, 13 Nov 2012 17:53:05 +0000

Changed in linux (Ubuntu Lucid):
status: Fix Committed → Fix Released
Launchpad Janitor (janitor) wrote :
Download full text (19.5 KiB)

This bug was fixed in the package linux - 3.2.0-34.53

---------------
linux (3.2.0-34.53) precise-proposed; urgency=low

  [Luis Henriques]

  * Release Tracking Bug
    - LP: #1078760

  [ Kamal Mostafa ]

  * SAUCE: input: Cypress PS/2 Trackpad list additional contributors

  [ Kyle Fazzari ]

  * SAUCE: input: Cypress PS/2 Trackpad fix multi-source, double-click
    - LP: #1055788
  * SAUCE: input: Cypress PS/2 Trackpad fix lost sync upon palm contact
    - LP: #1048258
  * SAUCE: input: Cypress PS/2 Trackpad fix taps turning into hardware
    clicks
    - LP: #1064086

  [ Tim Gardner ]

  * [Config] remove ndiswrapper from Provides:
    - LP: #1076395
  * [Config] CONFIG_HP_WATCHDOG=m for x86en
    - LP: #1076342

  [ Upstream Kernel Changes ]

  * Revert "SUNRPC: Ensure we close the socket on EPIPE errors too..."
    - LP: #1075355
  * Revert "ath9k_hw: Updated AR9003 tx gain table for 5GHz"
    - LP: #1075355
  * eCryptfs: check for eCryptfs cipher support at mount
    - LP: #338914
  * isci: fix isci_pci_probe() generates warning on efi failure path
    - LP: #1068162
  * mtd: nand: Use the mirror BBT descriptor when reading its version
    - LP: #1068162
  * drm/i915: prevent possible pin leak on error path
    - LP: #1068162
  * workqueue: add missing smp_wmb() in process_one_work()
    - LP: #1068162
  * TTY: ttyprintk, don't touch behind tty->write_buf
    - LP: #1068162
  * Remove BUG_ON from n_tty_read()
    - LP: #1068162
  * n_gsm.c: Implement 3GPP27.010 DLC start-up procedure in MUX
    - LP: #1068162
  * n_gsm: uplink SKBs accumulate on list
    - LP: #1068162
  * n_gsm : Flow control handling in Mux driver
    - LP: #1068162
  * char: n_gsm: remove message filtering for contipated DLCI
    - LP: #1068162
  * n_gsm: added interlocking for gsm_data_lock for certain code paths
    - LP: #1068162
  * n_gsm: avoid accessing freed memory during CMD_FCOFF condition
    - LP: #1068162
  * n_gsm: replace kfree_skb w/ appropriate dev_* versions
    - LP: #1068162
  * n_gsm: memory leak in uplink error path
    - LP: #1068162
  * UBI: fix autoresize handling in R/O mode
    - LP: #1068162
  * UBI: erase free PEB with bitflip in EC header
    - LP: #1068162
  * firmware: Add missing attributes to EFI variable attribute print out
    from sysfs
    - LP: #1068162
  * tools/hv: Fix exit() error code
    - LP: #1068162
  * slab: fix the DEADLOCK issue on l3 alien lock
    - LP: #1068162
  * gspca_pac7302: Add usb-id for 145f:013c
    - LP: #1068162
  * gspca_pac7302: add support for device 1ae7:2001 Speedlink Snappy
    Microphone SL-6825-SBK
    - LP: #1068162
  * xhci: Warn when hosts don't halt.
    - LP: #1068162
  * xHCI: add cmd_ring_state
    - LP: #1068162
  * xHCI: add aborting command ring function
    - LP: #1068162
  * xHCI: cancel command after command timeout
    - LP: #1068162
  * hpsa: Use LUN reset instead of target reset
    - LP: #1068162
  * rc: ite-cir: Initialise ite_dev::rdev earlier
    - LP: #1068162
  * staging: speakup_soft: Fix reading of init string
    - LP: #1068162
  * target: fix return code in target_core_init_configfs error path
    - LP: #1068162
  * powerpc/eeh: Lock module while handling EEH event
  ...

Changed in linux (Ubuntu Precise):
status: Fix Committed → Fix Released
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package linux-lts-quantal - 3.5.0-19.30~precise1

---------------
linux-lts-quantal (3.5.0-19.30~precise1) precise-proposed; urgency=low

  [Luis Henriques]

  * Release Tracking Bug
    - LP: #1078677

  [ Andy Whitcroft ]

  * UBUNTU: ensure we build signed packages for precise
    - LP: #1075181
  * [Config] update Vcs-git: to point to quantal
    - LP: #1069204

  [ Joseph Salisbury ]

  * SAUCE: ALSA: hda - add quirk for Thinkpad T430
    - LP: #1060372

  [ Tim Gardner ]

  * [Config] CONFIG_USB_OTG=n for all but armel/armhf
    - LP: #1047527
  * [Config] remove ndiswrapper from Provides:
    - LP: #1076395
  * [Config] ONFIG_AMD_IOMMU_V2=m
    - LP: #1071520

  [ Upstream Kernel Changes ]

  * kernel/sys.c: fix stack memory content leak via UNAME26
    - LP: #1065622, #1060521
    - CVE-2012-0957
  * use clamp_t in UNAME26 fix
    - LP: #1065622, #1060521
    - CVE-2012-0957
  * net: fix divide by zero in tcp algorithm illinois
    - LP: #1077091
    - CVE-2012-4565

  [ Wen-chien Jesse Sung ]

  * SAUCE: Bluetooth: Add a load_firmware callback to struct hci_dev
    - LP: #1065400
  * SAUCE: Bluetooth: Implement broadcom patchram firmware loader
    - LP: #1065400
  * SAUCE: Bluetooth: Add support for 13d3:3388 and 13d3:3389
    - LP: #1065400
 -- Luis Henriques <email address hidden> Wed, 14 Nov 2012 11:55:55 +0000

Changed in linux-lts-quantal (Ubuntu Precise):
status: Fix Committed → Fix Released
Launchpad Janitor (janitor) wrote :
Download full text (19.5 KiB)

This bug was fixed in the package linux-ti-omap4 - 3.2.0-1422.29

---------------
linux-ti-omap4 (3.2.0-1422.29) precise-proposed; urgency=low

  * Release Tracking Bug
    - LP: #1079562

  [ Paolo Pisati ]

  * rebased on Ubuntu-3.2.0-34.53

  [ Ubuntu: 3.2.0-34.53 ]

  * Release Tracking Bug
    - LP: #1078760
  * SAUCE: input: Cypress PS/2 Trackpad list additional contributors
  * SAUCE: input: Cypress PS/2 Trackpad fix multi-source, double-click
    - LP: #1055788
  * SAUCE: input: Cypress PS/2 Trackpad fix lost sync upon palm contact
    - LP: #1048258
  * SAUCE: input: Cypress PS/2 Trackpad fix taps turning into hardware
    clicks
    - LP: #1064086
  * [Config] remove ndiswrapper from Provides:
    - LP: #1076395
  * [Config] CONFIG_HP_WATCHDOG=m for x86en
    - LP: #1076342
  * Revert "SUNRPC: Ensure we close the socket on EPIPE errors too..."
    - LP: #1075355
  * Revert "ath9k_hw: Updated AR9003 tx gain table for 5GHz"
    - LP: #1075355
  * eCryptfs: check for eCryptfs cipher support at mount
    - LP: #338914
  * isci: fix isci_pci_probe() generates warning on efi failure path
    - LP: #1068162
  * mtd: nand: Use the mirror BBT descriptor when reading its version
    - LP: #1068162
  * drm/i915: prevent possible pin leak on error path
    - LP: #1068162
  * workqueue: add missing smp_wmb() in process_one_work()
    - LP: #1068162
  * TTY: ttyprintk, don't touch behind tty->write_buf
    - LP: #1068162
  * Remove BUG_ON from n_tty_read()
    - LP: #1068162
  * n_gsm.c: Implement 3GPP27.010 DLC start-up procedure in MUX
    - LP: #1068162
  * n_gsm: uplink SKBs accumulate on list
    - LP: #1068162
  * n_gsm : Flow control handling in Mux driver
    - LP: #1068162
  * char: n_gsm: remove message filtering for contipated DLCI
    - LP: #1068162
  * n_gsm: added interlocking for gsm_data_lock for certain code paths
    - LP: #1068162
  * n_gsm: avoid accessing freed memory during CMD_FCOFF condition
    - LP: #1068162
  * n_gsm: replace kfree_skb w/ appropriate dev_* versions
    - LP: #1068162
  * n_gsm: memory leak in uplink error path
    - LP: #1068162
  * UBI: fix autoresize handling in R/O mode
    - LP: #1068162
  * UBI: erase free PEB with bitflip in EC header
    - LP: #1068162
  * firmware: Add missing attributes to EFI variable attribute print out
    from sysfs
    - LP: #1068162
  * tools/hv: Fix exit() error code
    - LP: #1068162
  * slab: fix the DEADLOCK issue on l3 alien lock
    - LP: #1068162
  * gspca_pac7302: Add usb-id for 145f:013c
    - LP: #1068162
  * gspca_pac7302: add support for device 1ae7:2001 Speedlink Snappy
    Microphone SL-6825-SBK
    - LP: #1068162
  * xhci: Warn when hosts don't halt.
    - LP: #1068162
  * xHCI: add cmd_ring_state
    - LP: #1068162
  * xHCI: add aborting command ring function
    - LP: #1068162
  * xHCI: cancel command after command timeout
    - LP: #1068162
  * hpsa: Use LUN reset instead of target reset
    - LP: #1068162
  * rc: ite-cir: Initialise ite_dev::rdev earlier
    - LP: #1068162
  * staging: speakup_soft: Fix reading of init string
    - LP: #1068162
  * target: fix return code in target_core_init_configfs error path
    - LP: #1068162
  * powerpc/eeh: Lock ...

Changed in linux-ti-omap4 (Ubuntu Precise):
status: Fix Committed → Fix Released
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package linux - 3.5.0-19.30

---------------
linux (3.5.0-19.30) quantal-proposed; urgency=low

  [Luis Henriques]

  * Release Tracking Bug
    - LP: #1078041

  [ Andy Whitcroft ]

  * [Config] update Vcs-git: to point to quantal
    - LP: #1069204

  [ Joseph Salisbury ]

  * SAUCE: ALSA: hda - add quirk for Thinkpad T430
    - LP: #1060372

  [ Tim Gardner ]

  * [Config] CONFIG_USB_OTG=n for all but armel/armhf
    - LP: #1047527
  * [Config] remove ndiswrapper from Provides:
    - LP: #1076395
  * [Config] ONFIG_AMD_IOMMU_V2=m
    - LP: #1071520

  [ Upstream Kernel Changes ]

  * kernel/sys.c: fix stack memory content leak via UNAME26
    - LP: #1065622, #1060521
    - CVE-2012-0957
  * use clamp_t in UNAME26 fix
    - LP: #1065622, #1060521
    - CVE-2012-0957
  * net: fix divide by zero in tcp algorithm illinois
    - LP: #1077091
    - CVE-2012-4565

  [ Wen-chien Jesse Sung ]

  * SAUCE: Bluetooth: Add a load_firmware callback to struct hci_dev
    - LP: #1065400
  * SAUCE: Bluetooth: Implement broadcom patchram firmware loader
    - LP: #1065400
  * SAUCE: Bluetooth: Add support for 13d3:3388 and 13d3:3389
    - LP: #1065400
 -- Luis Henriques <email address hidden> Tue, 13 Nov 2012 15:49:15 +0000

Changed in linux (Ubuntu Quantal):
status: Fix Committed → Fix Released
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package linux-ti-omap4 - 3.5.0-215.22

---------------
linux-ti-omap4 (3.5.0-215.22) quantal-proposed; urgency=low

  * Release Tracking Bug
    - LP: #1078672

  [ Paolo Pisati ]

  * rebased on Ubuntu-3.5.0-19.30

  [ Ubuntu: 3.5.0-19.30 ]

  * Release Tracking Bug
    - LP: #1078041
  * [Config] update Vcs-git: to point to quantal
    - LP: #1069204
  * SAUCE: ALSA: hda - add quirk for Thinkpad T430
    - LP: #1060372
  * [Config] CONFIG_USB_OTG=n for all but armel/armhf
    - LP: #1047527
  * [Config] remove ndiswrapper from Provides:
    - LP: #1076395
  * [Config] ONFIG_AMD_IOMMU_V2=m
    - LP: #1071520
  * kernel/sys.c: fix stack memory content leak via UNAME26
    - LP: #1065622, #1060521
    - CVE-2012-0957
  * use clamp_t in UNAME26 fix
    - LP: #1065622, #1060521
    - CVE-2012-0957
  * net: fix divide by zero in tcp algorithm illinois
    - LP: #1077091
    - CVE-2012-4565
  * SAUCE: Bluetooth: Add a load_firmware callback to struct hci_dev
    - LP: #1065400
  * SAUCE: Bluetooth: Implement broadcom patchram firmware loader
    - LP: #1065400
  * SAUCE: Bluetooth: Add support for 13d3:3388 and 13d3:3389
    - LP: #1065400
 -- Paolo Pisati <email address hidden> Fri, 16 Nov 2012 10:39:59 +0100

Changed in linux-ti-omap4 (Ubuntu Quantal):
status: Fix Committed → Fix Released
Changed in linux-ti-omap4 (Ubuntu Raring):
status: Fix Committed → Fix Released
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package linux-ec2 - 2.6.32-350.57

---------------
linux-ec2 (2.6.32-350.57) lucid-proposed; urgency=low

  [ Stefan Bader ]

  * Rebased to Ubuntu-2.6.32-45.100
  * Release Tracking Bug
    - LP: #1078882

  [ Ubuntu: 2.6.32-45.100 ]

  * eCryptfs: check for eCryptfs cipher support at mount
    - LP: #338914
  * net: fix divide by zero in tcp algorithm illinois
    - LP: #1077091
    - CVE-2012-4565
 -- Stefan Bader <email address hidden> Thu, 15 Nov 2012 11:23:05 +0100

Changed in linux-ec2 (Ubuntu Lucid):
status: Fix Committed → Fix Released
Launchpad Janitor (janitor) wrote :
Download full text (19.5 KiB)

This bug was fixed in the package linux-armadaxp - 3.2.0-1611.16

---------------
linux-armadaxp (3.2.0-1611.16) precise-proposed; urgency=low

  * Release Tracking Bug
    -LP: #1079563
  * Rebase on Ubuntu-3.2.0-34.53

  [ Ubuntu: 3.2.0-34.53 ]

  * Release Tracking Bug
    - LP: #1078760
  * SAUCE: input: Cypress PS/2 Trackpad list additional contributors
  * SAUCE: input: Cypress PS/2 Trackpad fix multi-source, double-click
    - LP: #1055788
  * SAUCE: input: Cypress PS/2 Trackpad fix lost sync upon palm contact
    - LP: #1048258
  * SAUCE: input: Cypress PS/2 Trackpad fix taps turning into hardware
    clicks
    - LP: #1064086
  * [Config] remove ndiswrapper from Provides:
    - LP: #1076395
  * [Config] CONFIG_HP_WATCHDOG=m for x86en
    - LP: #1076342
  * Revert "SUNRPC: Ensure we close the socket on EPIPE errors too..."
    - LP: #1075355
  * Revert "ath9k_hw: Updated AR9003 tx gain table for 5GHz"
    - LP: #1075355
  * eCryptfs: check for eCryptfs cipher support at mount
    - LP: #338914
  * isci: fix isci_pci_probe() generates warning on efi failure path
    - LP: #1068162
  * mtd: nand: Use the mirror BBT descriptor when reading its version
    - LP: #1068162
  * drm/i915: prevent possible pin leak on error path
    - LP: #1068162
  * workqueue: add missing smp_wmb() in process_one_work()
    - LP: #1068162
  * TTY: ttyprintk, don't touch behind tty->write_buf
    - LP: #1068162
  * Remove BUG_ON from n_tty_read()
    - LP: #1068162
  * n_gsm.c: Implement 3GPP27.010 DLC start-up procedure in MUX
    - LP: #1068162
  * n_gsm: uplink SKBs accumulate on list
    - LP: #1068162
  * n_gsm : Flow control handling in Mux driver
    - LP: #1068162
  * char: n_gsm: remove message filtering for contipated DLCI
    - LP: #1068162
  * n_gsm: added interlocking for gsm_data_lock for certain code paths
    - LP: #1068162
  * n_gsm: avoid accessing freed memory during CMD_FCOFF condition
    - LP: #1068162
  * n_gsm: replace kfree_skb w/ appropriate dev_* versions
    - LP: #1068162
  * n_gsm: memory leak in uplink error path
    - LP: #1068162
  * UBI: fix autoresize handling in R/O mode
    - LP: #1068162
  * UBI: erase free PEB with bitflip in EC header
    - LP: #1068162
  * firmware: Add missing attributes to EFI variable attribute print out
    from sysfs
    - LP: #1068162
  * tools/hv: Fix exit() error code
    - LP: #1068162
  * slab: fix the DEADLOCK issue on l3 alien lock
    - LP: #1068162
  * gspca_pac7302: Add usb-id for 145f:013c
    - LP: #1068162
  * gspca_pac7302: add support for device 1ae7:2001 Speedlink Snappy
    Microphone SL-6825-SBK
    - LP: #1068162
  * xhci: Warn when hosts don't halt.
    - LP: #1068162
  * xHCI: add cmd_ring_state
    - LP: #1068162
  * xHCI: add aborting command ring function
    - LP: #1068162
  * xHCI: cancel command after command timeout
    - LP: #1068162
  * hpsa: Use LUN reset instead of target reset
    - LP: #1068162
  * rc: ite-cir: Initialise ite_dev::rdev earlier
    - LP: #1068162
  * staging: speakup_soft: Fix reading of init string
    - LP: #1068162
  * target: fix return code in target_core_init_configfs error path
    - LP: #1068162
  * powerpc/eeh: Lock module while handling E...

Changed in linux-armadaxp (Ubuntu Precise):
status: Fix Committed → Fix Released
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package linux-armadaxp - 3.5.0-1605.7

---------------
linux-armadaxp (3.5.0-1605.7) quantal-proposed; urgency=low

  [ Ike Panhc ]

  * Release Tracking Bug
    - LP: #1078674
  * Rebase onto Ubuntu-3.5.0-19.30

  [ Ubuntu: 3.5.0-19.30 ]

  * Release Tracking Bug
    - LP: #1078041
  * [Config] update Vcs-git: to point to quantal
    - LP: #1069204
  * SAUCE: ALSA: hda - add quirk for Thinkpad T430
    - LP: #1060372
  * [Config] CONFIG_USB_OTG=n for all but armel/armhf
    - LP: #1047527
  * [Config] remove ndiswrapper from Provides:
    - LP: #1076395
  * [Config] ONFIG_AMD_IOMMU_V2=m
    - LP: #1071520
  * kernel/sys.c: fix stack memory content leak via UNAME26
    - LP: #1065622, #1060521
    - CVE-2012-0957
  * use clamp_t in UNAME26 fix
    - LP: #1065622, #1060521
    - CVE-2012-0957
  * net: fix divide by zero in tcp algorithm illinois
    - LP: #1077091
    - CVE-2012-4565
  * SAUCE: Bluetooth: Add a load_firmware callback to struct hci_dev
    - LP: #1065400
  * SAUCE: Bluetooth: Implement broadcom patchram firmware loader
    - LP: #1065400
  * SAUCE: Bluetooth: Add support for 13d3:3388 and 13d3:3389
    - LP: #1065400
 -- Ike Panhc <email address hidden> Wed, 21 Nov 2012 15:52:25 +0800

Changed in linux-armadaxp (Ubuntu Quantal):
status: Fix Committed → Fix Released
Changed in linux-armadaxp (Ubuntu Raring):
status: Fix Committed → Fix Released
description: updated
Changed in linux-lts-backport-natty (Ubuntu Lucid):
status: New → Won't Fix
Changed in linux-lts-backport-natty (Ubuntu Oneiric):
status: New → Invalid
Changed in linux-lts-backport-natty (Ubuntu Precise):
status: New → Invalid
Changed in linux-lts-backport-natty (Ubuntu Quantal):
status: New → Invalid
Changed in linux-lts-backport-natty (Ubuntu Raring):
status: New → Invalid
Changed in linux-lts-backport-natty (Ubuntu Hardy):
status: New → Invalid
Changed in linux-lts-backport-natty (Ubuntu):
status: New → Won't Fix
Changed in linux-lts-backport-natty (Ubuntu Oneiric):
status: Invalid → Won't Fix
Changed in linux-lts-backport-natty (Ubuntu Precise):
status: Invalid → Won't Fix
Changed in linux-lts-backport-natty (Ubuntu Quantal):
status: Invalid → Won't Fix
Changed in linux-lts-backport-natty (Ubuntu Raring):
status: Invalid → Won't Fix
Changed in linux-lts-backport-natty (Ubuntu Hardy):
status: Invalid → Won't Fix
To post a comment you must log in.
This report contains Public Security information  Edit
Everyone can see this security related information.

Other bug subscribers