CVE-2011-1748
Bug #788694 reported by
Andy Whitcroft
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
linux (Ubuntu) |
Fix Released
|
Low
|
Unassigned | ||
Dapper |
Invalid
|
Undecided
|
Unassigned | ||
Hardy |
Invalid
|
Low
|
Unassigned | ||
Lucid |
Fix Released
|
Low
|
Unassigned | ||
Maverick |
Fix Released
|
Low
|
Andy Whitcroft | ||
Natty |
Fix Released
|
Low
|
Unassigned | ||
Oneiric |
Fix Released
|
Low
|
Unassigned | ||
linux-ec2 (Ubuntu) |
Invalid
|
Low
|
Unassigned | ||
Dapper |
Invalid
|
Undecided
|
Unassigned | ||
Hardy |
Invalid
|
Low
|
Unassigned | ||
Lucid |
Fix Released
|
Low
|
Unassigned | ||
Maverick |
Invalid
|
Low
|
Unassigned | ||
Natty |
Invalid
|
Low
|
Unassigned | ||
Oneiric |
Invalid
|
Low
|
Unassigned | ||
linux-fsl-imx51 (Ubuntu) |
Invalid
|
Low
|
Unassigned | ||
Dapper |
Invalid
|
Undecided
|
Unassigned | ||
Hardy |
Invalid
|
Low
|
Unassigned | ||
Lucid |
Fix Released
|
Low
|
Paolo Pisati | ||
Maverick |
Invalid
|
Low
|
Unassigned | ||
Natty |
Invalid
|
Low
|
Unassigned | ||
Oneiric |
Invalid
|
Low
|
Unassigned | ||
linux-lts-backport-maverick (Ubuntu) |
Invalid
|
Low
|
Unassigned | ||
Dapper |
Invalid
|
Undecided
|
Unassigned | ||
Hardy |
Invalid
|
Low
|
Unassigned | ||
Lucid |
Fix Released
|
Low
|
Unassigned | ||
Maverick |
Invalid
|
Low
|
Unassigned | ||
Natty |
Invalid
|
Low
|
Unassigned | ||
Oneiric |
Invalid
|
Low
|
Unassigned | ||
linux-lts-backport-natty (Ubuntu) |
Invalid
|
Low
|
Unassigned | ||
Dapper |
Invalid
|
Undecided
|
Unassigned | ||
Hardy |
Invalid
|
Low
|
Unassigned | ||
Lucid |
Invalid
|
Low
|
Unassigned | ||
Maverick |
Invalid
|
Low
|
Unassigned | ||
Natty |
Invalid
|
Low
|
Unassigned | ||
Oneiric |
Invalid
|
Low
|
Unassigned | ||
linux-mvl-dove (Ubuntu) |
Invalid
|
Low
|
Unassigned | ||
Dapper |
Invalid
|
Undecided
|
Unassigned | ||
Hardy |
Invalid
|
Low
|
Unassigned | ||
Lucid |
Fix Released
|
Low
|
Paolo Pisati | ||
Maverick |
Fix Released
|
Low
|
Unassigned | ||
Natty |
Invalid
|
Low
|
Unassigned | ||
Oneiric |
Invalid
|
Low
|
Unassigned | ||
linux-ti-omap4 (Ubuntu) |
Fix Released
|
Low
|
Paolo Pisati | ||
Dapper |
Invalid
|
Undecided
|
Unassigned | ||
Hardy |
Invalid
|
Low
|
Unassigned | ||
Lucid |
Invalid
|
Low
|
Unassigned | ||
Maverick |
Fix Released
|
Low
|
Paolo Pisati | ||
Natty |
Fix Released
|
Low
|
Paolo Pisati | ||
Oneiric |
Fix Released
|
Low
|
Paolo Pisati |
Bug Description
The raw_release function in net/can/raw.c in the Linux kernel before 2.6.39-rc6 does not properly validate a socket data structure, which allows local users to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via a crafted release operation.
Break-Fix: - 10022a6c66e199d
Related branches
CVE References
- 2010-3296
- 2010-3297
- 2010-3698
- 2010-3858
- 2010-3859
- 2010-3865
- 2010-3875
- 2010-3876
- 2010-3877
- 2010-3880
- 2010-4073
- 2010-4076
- 2010-4077
- 2010-4079
- 2010-4080
- 2010-4081
- 2010-4082
- 2010-4083
- 2010-4157
- 2010-4162
- 2010-4163
- 2010-4164
- 2010-4169
- 2010-4175
- 2010-4242
- 2010-4243
- 2010-4248
- 2010-4256
- 2010-4258
- 2010-4342
- 2010-4346
- 2010-4527
- 2010-4529
- 2010-4565
- 2010-4649
- 2010-4656
- 2011-0463
- 2011-0521
- 2011-0695
- 2011-0711
- 2011-0712
- 2011-0726
- 2011-1010
- 2011-1012
- 2011-1013
- 2011-1016
- 2011-1017
- 2011-1019
- 2011-1020
- 2011-1078
- 2011-1079
- 2011-1080
- 2011-1082
- 2011-1090
- 2011-1093
- 2011-1160
- 2011-1163
- 2011-1169
- 2011-1170
- 2011-1171
- 2011-1172
- 2011-1173
- 2011-1180
- 2011-1478
- 2011-1493
- 2011-1494
- 2011-1577
- 2011-1598
- 2011-1746
- 2011-1748
- 2011-1770
- 2011-1833
- 2011-2484
- 2011-2492
- 2011-2534
- 2011-2699
- 2011-2918
tags: | added: kernel-cve-tracking-bug |
security vulnerability: | no → yes |
Changed in linux (Ubuntu Dapper): | |
status: | New → Invalid |
Changed in linux (Ubuntu Natty): | |
status: | New → Fix Released |
Changed in linux (Ubuntu Oneiric): | |
status: | New → Fix Released |
Changed in linux (Ubuntu Lucid): | |
status: | New → Fix Released |
Changed in linux (Ubuntu Hardy): | |
status: | New → Invalid |
description: | updated |
Changed in linux (Ubuntu Maverick): | |
assignee: | nobody → Andy Whitcroft (apw) |
status: | New → In Progress |
Changed in linux-fsl-imx51 (Ubuntu Dapper): | |
status: | New → Invalid |
Changed in linux-fsl-imx51 (Ubuntu Hardy): | |
status: | New → Invalid |
Changed in linux-fsl-imx51 (Ubuntu Maverick): | |
status: | New → Invalid |
Changed in linux-fsl-imx51 (Ubuntu Natty): | |
status: | New → Invalid |
Changed in linux-fsl-imx51 (Ubuntu Oneiric): | |
status: | New → Invalid |
Changed in linux-mvl-dove (Ubuntu Dapper): | |
status: | New → Invalid |
Changed in linux-mvl-dove (Ubuntu Hardy): | |
status: | New → Invalid |
Changed in linux-mvl-dove (Ubuntu Natty): | |
status: | New → Invalid |
Changed in linux-mvl-dove (Ubuntu Oneiric): | |
status: | New → Invalid |
Changed in linux-ti-omap4 (Ubuntu Dapper): | |
status: | New → Invalid |
Changed in linux-ti-omap4 (Ubuntu Hardy): | |
status: | New → Invalid |
Changed in linux-ti-omap4 (Ubuntu Lucid): | |
status: | New → Invalid |
Changed in linux-fsl-imx51 (Ubuntu Lucid): | |
assignee: | nobody → Paolo Pisati (p-pisati) |
status: | New → In Progress |
Changed in linux-mvl-dove (Ubuntu Lucid): | |
assignee: | nobody → Paolo Pisati (p-pisati) |
status: | New → In Progress |
Changed in linux-ti-omap4 (Ubuntu Maverick): | |
assignee: | nobody → Paolo Pisati (p-pisati) |
status: | New → In Progress |
Changed in linux-ti-omap4 (Ubuntu Natty): | |
assignee: | nobody → Paolo Pisati (p-pisati) |
status: | New → In Progress |
Changed in linux-ti-omap4 (Ubuntu Oneiric): | |
assignee: | nobody → Paolo Pisati (p-pisati) |
status: | New → In Progress |
Changed in linux-lts-backport-maverick (Ubuntu Maverick): | |
status: | New → Invalid |
Changed in linux-lts-backport-maverick (Ubuntu Natty): | |
status: | New → Invalid |
Changed in linux-lts-backport-maverick (Ubuntu Oneiric): | |
status: | New → Invalid |
Changed in linux-lts-backport-maverick (Ubuntu Dapper): | |
status: | New → Invalid |
Changed in linux-lts-backport-maverick (Ubuntu Hardy): | |
status: | New → Invalid |
Changed in linux-mvl-dove (Ubuntu Lucid): | |
status: | In Progress → Fix Released |
Changed in linux-mvl-dove (Ubuntu Maverick): | |
status: | New → Fix Released |
Changed in linux-lts-backport-maverick (Ubuntu Lucid): | |
status: | New → Fix Committed |
Changed in linux-ti-omap4 (Ubuntu Oneiric): | |
status: | In Progress → Fix Committed |
Changed in linux-ti-omap4 (Ubuntu Maverick): | |
status: | In Progress → Fix Committed |
Changed in linux-ti-omap4 (Ubuntu Natty): | |
status: | In Progress → Fix Committed |
description: | updated |
Changed in linux-ec2 (Ubuntu Dapper): | |
status: | New → Invalid |
Changed in linux-lts-backport-natty (Ubuntu Dapper): | |
status: | New → Invalid |
Changed in linux-ec2 (Ubuntu Lucid): | |
status: | New → Fix Released |
Changed in linux-ec2 (Ubuntu Oneiric): | |
status: | New → Invalid |
Changed in linux-ec2 (Ubuntu Hardy): | |
status: | New → Invalid |
Changed in linux-ec2 (Ubuntu Maverick): | |
status: | New → Invalid |
Changed in linux-ec2 (Ubuntu Natty): | |
status: | New → Invalid |
Changed in linux-lts-backport-natty (Ubuntu Lucid): | |
status: | New → Invalid |
Changed in linux-lts-backport-natty (Ubuntu Oneiric): | |
status: | New → Invalid |
Changed in linux-lts-backport-natty (Ubuntu Hardy): | |
status: | New → Invalid |
Changed in linux-lts-backport-natty (Ubuntu Maverick): | |
status: | New → Invalid |
Changed in linux-lts-backport-natty (Ubuntu Natty): | |
status: | New → Invalid |
description: | updated |
Changed in linux-ec2 (Ubuntu Lucid): | |
importance: | Undecided → Low |
Changed in linux-ec2 (Ubuntu Oneiric): | |
importance: | Undecided → Low |
Changed in linux-ec2 (Ubuntu Hardy): | |
importance: | Undecided → Low |
Changed in linux-ec2 (Ubuntu Maverick): | |
importance: | Undecided → Low |
Changed in linux-ec2 (Ubuntu Natty): | |
importance: | Undecided → Low |
Changed in linux-lts-backport-natty (Ubuntu Lucid): | |
importance: | Undecided → Low |
Changed in linux-lts-backport-natty (Ubuntu Oneiric): | |
importance: | Undecided → Low |
Changed in linux-lts-backport-natty (Ubuntu Hardy): | |
importance: | Undecided → Low |
Changed in linux-lts-backport-natty (Ubuntu Maverick): | |
importance: | Undecided → Low |
Changed in linux-lts-backport-natty (Ubuntu Natty): | |
importance: | Undecided → Low |
Changed in linux-mvl-dove (Ubuntu Lucid): | |
importance: | Undecided → Low |
Changed in linux-mvl-dove (Ubuntu Oneiric): | |
importance: | Undecided → Low |
Changed in linux-mvl-dove (Ubuntu Hardy): | |
importance: | Undecided → Low |
Changed in linux-mvl-dove (Ubuntu Maverick): | |
importance: | Undecided → Low |
Changed in linux-mvl-dove (Ubuntu Natty): | |
importance: | Undecided → Low |
Changed in linux-lts-backport-maverick (Ubuntu Lucid): | |
importance: | Undecided → Low |
Changed in linux-lts-backport-maverick (Ubuntu Oneiric): | |
importance: | Undecided → Low |
Changed in linux-lts-backport-maverick (Ubuntu Hardy): | |
importance: | Undecided → Low |
Changed in linux-lts-backport-maverick (Ubuntu Maverick): | |
importance: | Undecided → Low |
Changed in linux-lts-backport-maverick (Ubuntu Natty): | |
importance: | Undecided → Low |
Changed in linux (Ubuntu Lucid): | |
importance: | Undecided → Low |
Changed in linux (Ubuntu Oneiric): | |
importance: | Undecided → Low |
Changed in linux (Ubuntu Hardy): | |
importance: | Undecided → Low |
Changed in linux (Ubuntu Maverick): | |
importance: | Undecided → Low |
Changed in linux (Ubuntu Natty): | |
importance: | Undecided → Low |
Changed in linux-ti-omap4 (Ubuntu Lucid): | |
importance: | Undecided → Low |
Changed in linux-ti-omap4 (Ubuntu Oneiric): | |
importance: | Undecided → Low |
Changed in linux-ti-omap4 (Ubuntu Hardy): | |
importance: | Undecided → Low |
Changed in linux-ti-omap4 (Ubuntu Maverick): | |
importance: | Undecided → Low |
Changed in linux-ti-omap4 (Ubuntu Natty): | |
importance: | Undecided → Low |
Changed in linux-fsl-imx51 (Ubuntu Lucid): | |
importance: | Undecided → Low |
Changed in linux-fsl-imx51 (Ubuntu Oneiric): | |
importance: | Undecided → Low |
Changed in linux-fsl-imx51 (Ubuntu Hardy): | |
importance: | Undecided → Low |
Changed in linux-fsl-imx51 (Ubuntu Maverick): | |
importance: | Undecided → Low |
Changed in linux-fsl-imx51 (Ubuntu Natty): | |
importance: | Undecided → Low |
Changed in linux-ti-omap4 (Ubuntu Natty): | |
status: | Fix Committed → Fix Released |
Changed in linux-ti-omap4 (Ubuntu Oneiric): | |
status: | Fix Committed → Fix Released |
Changed in linux-ti-omap4 (Ubuntu): | |
status: | Fix Committed → Fix Released |
To post a comment you must log in.
This bug was fixed in the package linux - 2.6.35-30.54
---------------
linux (2.6.35-30.54) maverick-proposed; urgency=low
[ Brad Figg ]
* Release Tracking Bug
- LP: #794114
[ Upstream Kernel Changes ]
* Revert "xhci: Fix full speed bInterval encoding." endpoint_ interval( )"
* Revert "USB: xhci - also free streams when resetting devices"
* Revert "USB: xhci - fix math in xhci_get_
* Revert "USB: xhci - fix unsafe macro definitions"
linux (2.6.35-30.53) maverick-proposed; urgency=low
[ Upstream Kernel Changes ]
* xhci: Fix full speed bInterval encoding.
- LP: #792959
linux (2.6.35-30.52) maverick-proposed; urgency=low
[ Herton R. Krzesinski ]
* Release Tracking Bug
- LP: #790653
[ Stefan Bader ]
* Include nls_iso8859-1 for virtual images
- LP: #732046
[ Thomas Schlichter ]
* SAUCE: vesafb: mtrr module parameter is uint, not bool
- LP: #778043
[ Tim Gardner ]
* [Config] Add cachefiles.ko to virtual flavour
- LP: #770430
[ Upstream Kernel Changes ]
* Revert "intel_idle: PCI quirk to prevent Lenovo Ideapad s10-3 boot ldm.c: fix oops caused by corrupted partition table, space_info
hang"
- LP: #772560
* Revert "TPM: Long default timeout fix"
- LP: #772560
* Revert "tpm_tis: Use timeouts returned from TPM"
- LP: #772560
* Revert "xen: set max_pfn_mapped to the last pfn mapped"
* CAN: Use inode instead of kernel address for /proc file, CVE-2010-4565
- LP: #765007
- CVE-2010-4565
* xfs: prevent leaking uninitialized stack memory in FSGEOMETRY_V1,
CVE-2011-0711
- LP: #767740
- CVE-2011-0711
* Treat writes as new when holes span across page boundaries,
CVE-2011-0463
- LP: #770483
- CVE-2011-0463
* fs/partitions/
CVE-2011-1017
- LP: #771382
- CVE-2011-1017
* qla2xxx: Make the FC port capability mutual exclusive.
- LP: #772560
* staging: usbip: bugfixes related to kthread conversion
- LP: #772560
* staging: usbip: bugfix add number of packets for isochronous frames
- LP: #772560
* staging: usbip: bugfix for isochronous packets and optimization
- LP: #772560
* staging: hv: Fix GARP not sent after Quick Migration
- LP: #772560
* staging: hv: use sync_bitops when interacting with the hypervisor
- LP: #772560
* irda: validate peer name and attribute lengths
- LP: #772560
* irda: prevent heap corruption on invalid nickname
- LP: #772560
* nilfs2: fix data loss in mmap page write for hole blocks
- LP: #772560
* ASoC: Explicitly say registerless widgets have no register
- LP: #772560
* ALSA: ens1371: fix Creative Ectiva support
- LP: #772560
* ROSE: prevent heap corruption with bad facilities
- LP: #772560
* Btrfs: Fix uninitialized root flags for subvolumes
- LP: #772560
* x86, mtrr, pat: Fix one cpu getting out of sync during resume
- LP: #772560
* UBIFS: do not read flash unnecessarily
- LP: #772560
* UBIFS: fix oops on error path in read_pnode
- LP: #772560
* UBIFS: fix debugging failure in dbg_check_
- LP: #772560
* quota: Don't write quota info in dquot_commit()
- LP: #772560
* mm: avoid wrapping vm_...