CVE-2010-4263

Bug #737024 reported by Leann Ogasawara
258
This bug affects 1 person
Affects Status Importance Assigned to Milestone
linux (Ubuntu)
Invalid
Undecided
Unassigned
Dapper
Invalid
Undecided
Unassigned
Hardy
Invalid
Undecided
Unassigned
Karmic
Invalid
Undecided
Unassigned
Lucid
Fix Released
Medium
Leann Ogasawara
Maverick
Invalid
Undecided
Unassigned
Natty
Invalid
Undecided
Unassigned
linux-fsl-imx51 (Ubuntu)
Invalid
Undecided
Unassigned
Dapper
Invalid
Undecided
Unassigned
Hardy
Invalid
Undecided
Unassigned
Karmic
Won't Fix
Undecided
Unassigned
Lucid
Invalid
Undecided
Unassigned
Maverick
Invalid
Undecided
Unassigned
Natty
Invalid
Undecided
Unassigned
linux-lts-backport-maverick (Ubuntu)
Invalid
Undecided
Unassigned
Dapper
Won't Fix
Undecided
Unassigned
Hardy
Won't Fix
Undecided
Unassigned
Karmic
Won't Fix
Undecided
Unassigned
Lucid
Won't Fix
Undecided
Unassigned
Maverick
Won't Fix
Undecided
Unassigned
Natty
Invalid
Undecided
Unassigned
linux-mvl-dove (Ubuntu)
Invalid
Undecided
Unassigned
Dapper
Invalid
Undecided
Unassigned
Hardy
Invalid
Undecided
Unassigned
Karmic
Invalid
Undecided
Unassigned
Lucid
Fix Released
Undecided
Paolo Pisati
Maverick
Fix Released
Undecided
Paolo Pisati
Natty
Invalid
Undecided
Unassigned
linux-ti-omap4 (Ubuntu)
Invalid
Undecided
Unassigned
Dapper
Invalid
Undecided
Unassigned
Hardy
Invalid
Undecided
Unassigned
Karmic
Invalid
Undecided
Unassigned
Lucid
Invalid
Undecided
Unassigned
Maverick
Invalid
Undecided
Unassigned
Natty
Invalid
Undecided
Unassigned

Bug Description

The igb_receive_skb function in drivers/net/igb/igb_main.c in the Intel
Gigabit Ethernet (aka igb) subsystem in the Linux kernel before 2.6.34,
when Single Root I/O Virtualization (SR-IOV) and promiscuous mode are
enabled but no VLANs are registered, allows remote attackers to cause a
denial of service (NULL pointer dereference and panic) and possibly have
unspecified other impact via a VLAN tagged frame.

security vulnerability: no → yes
description: updated
Revision history for this message
Leann Ogasawara (leannogasawara) wrote :
Changed in linux (Ubuntu Dapper):
status: New → Invalid
Changed in linux (Ubuntu Hardy):
status: New → Invalid
Changed in linux (Ubuntu Karmic):
status: New → Invalid
Changed in linux (Ubuntu Lucid):
assignee: nobody → Leann Ogasawara (leannogasawara)
importance: Undecided → Medium
status: New → In Progress
Changed in linux (Ubuntu Maverick):
status: New → Invalid
Changed in linux (Ubuntu Natty):
status: New → Invalid
Tim Gardner (timg-tpi)
Changed in linux (Ubuntu Lucid):
status: In Progress → Fix Committed
Changed in linux-mvl-dove (Ubuntu Natty):
status: New → Invalid
Changed in linux-lts-backport-maverick (Ubuntu Natty):
status: New → Invalid
Changed in linux-fsl-imx51 (Ubuntu Natty):
status: New → Invalid
Paolo Pisati (p-pisati)
Changed in linux-ti-omap4 (Ubuntu Maverick):
status: New → Invalid
Changed in linux-ti-omap4 (Ubuntu Lucid):
status: New → Invalid
Changed in linux-ti-omap4 (Ubuntu Karmic):
status: New → Invalid
Changed in linux-ti-omap4 (Ubuntu Hardy):
status: New → Invalid
Changed in linux-ti-omap4 (Ubuntu Dapper):
status: New → Invalid
Changed in linux-ti-omap4 (Ubuntu Natty):
status: New → Invalid
Paolo Pisati (p-pisati)
Changed in linux-mvl-dove (Ubuntu Dapper):
status: New → Invalid
Changed in linux-mvl-dove (Ubuntu Hardy):
status: New → Invalid
Changed in linux-mvl-dove (Ubuntu Karmic):
status: New → Invalid
Changed in linux-mvl-dove (Ubuntu Maverick):
assignee: nobody → Paolo Pisati (p-pisati)
Changed in linux-mvl-dove (Ubuntu Natty):
assignee: nobody → Paolo Pisati (p-pisati)
assignee: Paolo Pisati (p-pisati) → nobody
Changed in linux-mvl-dove (Ubuntu Lucid):
assignee: nobody → Paolo Pisati (p-pisati)
Brad Figg (brad-figg)
tags: added: kernel-cve-tracking-bug
Paolo Pisati (p-pisati)
Changed in linux (Ubuntu Lucid):
status: Fix Committed → Fix Released
Paolo Pisati (p-pisati)
Changed in linux-mvl-dove (Ubuntu Lucid):
status: New → In Progress
Revision history for this message
Paolo Pisati (p-pisati) wrote :

karmic is EOL

Changed in linux-fsl-imx51 (Ubuntu Dapper):
status: New → Invalid
Changed in linux-fsl-imx51 (Ubuntu Hardy):
status: New → Invalid
Changed in linux-fsl-imx51 (Ubuntu Maverick):
status: New → Invalid
Changed in linux-fsl-imx51 (Ubuntu Karmic):
status: New → Won't Fix
Revision history for this message
Paolo Pisati (p-pisati) wrote :

in igb_receive_skb() we already check if vlans are registered to this adapter: no need for this fix.

Changed in linux-fsl-imx51 (Ubuntu Lucid):
status: New → Invalid
Revision history for this message
Paolo Pisati (p-pisati) wrote :

in igb_receive_skb() we already check for the vlan to be attached to the NIC: no need for this fix.

Revision history for this message
Launchpad Janitor (janitor) wrote :
Download full text (29.1 KiB)

This bug was fixed in the package linux-mvl-dove - 2.6.32-217.34

---------------
linux-mvl-dove (2.6.32-217.34) lucid-proposed; urgency=low

  [ Herton R. Krzesinski ]

  * Release Tracking Bug
    - LP: #794695

  [ Paolo Pisati ]

  * Rebased to 2.6.32-33.66

  [ Ubuntu: 2.6.32-33.66 ]

  * Release Tracking Bug
    - LP: #794098
  * Revert "xhci: Fix full speed bInterval encoding."
  * Revert "USB: xhci - fix math in xhci_get_endpoint_interval()"
  * Revert "USB: xhci - fix unsafe macro definitions"

  [ Ubuntu: 2.6.32-33.65 ]

  * xhci: Fix full speed bInterval encoding.
    - LP: #792959

  [ Ubuntu: 2.6.32-33.64 ]

   * Release Tracking Bug
     - LP: #789325
  * SAUCE: (no-up) Fix up KVM: VMX: Fix host userspace gsbase corruption
    - LP: #787675
  * SAUCE: vesafb: mtrr module parameter is uint, not bool
    - LP: #778043
  * Revert "(pre-stable): input: Support Clickpad devices in ClickZone
    mode"
    - LP: #780588
  * Revert "GFS2: Fix writing to non-page aligned gfs2_quota structures"
    - LP: #780588
  * Revert "mmc: build fix: mmc_pm_notify is only available with
    CONFIG_PM=y"
    - LP: #780588
  * Revert "mmc: fix all hangs related to mmc/sd card insert/removal during
    suspend/resume"
    - LP: #780588
  * Revert "econet: fix CVE-2010-3848"
    - LP: #780588
  * Revert "dell-laptop: Add another Dell laptop family to the DMI
    whitelist"
    - LP: #780588
  * Revert "dell-laptop: Add another Dell laptop family to the DMI
    whitelist"
    - LP: #780588
  * Revert "xen: set max_pfn_mapped to the last pfn mapped"
  * cifs: always do is_path_accessible check in cifs_mount
    - LP: #770050
  * video: sn9c102: world-wirtable sysfs files
    - LP: #770050
  * UBIFS: restrict world-writable debugfs files
    - LP: #770050
  * NET: cdc-phonet, handle empty phonet header
    - LP: #770050
  * x86: Fix a bogus unwind annotation in lib/semaphore_32.S
    - LP: #770050
  * tioca: Fix assignment from incompatible pointer warnings
    - LP: #770050
  * mca.c: Fix cast from integer to pointer warning
    - LP: #770050
  * ramfs: fix memleak on no-mmu arch
    - LP: #770050
  * MAINTAINERS: update STABLE BRANCH info
    - LP: #770050
  * UBIFS: fix oops when R/O file-system is fsync'ed
    - LP: #770050
  * x86, cpu: AMD errata checking framework
    - LP: #770050
  * x86, cpu: Clean up AMD erratum 400 workaround
    - LP: #770050
  * x86, AMD: Set ARAT feature on AMD processors
    - LP: #770050
  * x86, amd: Disable GartTlbWlkErr when BIOS forgets it
    - LP: #770050
  * USB: ftdi_sio: Added IDs for CTI USB Serial Devices
    - LP: #770050
  * USB: ftdi_sio: add PID for OCT DK201 docking station
    - LP: #770050
  * USB: ftdi_sio: add ids for Hameg HO720 and HO730
    - LP: #770050
  * USB: option: Add new ONDA vendor id and product id for ONDA MT825UP
    - LP: #770050
  * USB: option: Added support for Samsung GT-B3730/GT-B3710 LTE USB modem.
    - LP: #770050
  * next_pidmap: fix overflow condition
    - LP: #770050
  * proc: do proper range check on readdir offset
    - LP: #770050
  * USB: EHCI: unlink unused QHs when the controller is stopped
    - LP: #770050
  * USB: fix formatting of SuperSpeed endpoints in /proc/bus/u...

Changed in linux-mvl-dove (Ubuntu Lucid):
status: In Progress → Fix Released
Revision history for this message
Launchpad Janitor (janitor) wrote :
Download full text (29.1 KiB)

This bug was fixed in the package linux-mvl-dove - 2.6.32-417.34

---------------
linux-mvl-dove (2.6.32-417.34) maverick-proposed; urgency=low

  [ Herton R. Krzesinski ]

  * Release Tracking Bug
    - LP: #795153

  [ Paolo Pisati ]

  * Rebased to 2.6.32-33.66

  [ Ubuntu: 2.6.32-33.66 ]

  * Release Tracking Bug
    - LP: #794098
  * Revert "xhci: Fix full speed bInterval encoding."
  * Revert "USB: xhci - fix math in xhci_get_endpoint_interval()"
  * Revert "USB: xhci - fix unsafe macro definitions"

  [ Ubuntu: 2.6.32-33.65 ]

  * xhci: Fix full speed bInterval encoding.
    - LP: #792959

  [ Ubuntu: 2.6.32-33.64 ]

   * Release Tracking Bug
     - LP: #789325
  * SAUCE: (no-up) Fix up KVM: VMX: Fix host userspace gsbase corruption
    - LP: #787675
  * SAUCE: vesafb: mtrr module parameter is uint, not bool
    - LP: #778043
  * Revert "(pre-stable): input: Support Clickpad devices in ClickZone
    mode"
    - LP: #780588
  * Revert "GFS2: Fix writing to non-page aligned gfs2_quota structures"
    - LP: #780588
  * Revert "mmc: build fix: mmc_pm_notify is only available with
    CONFIG_PM=y"
    - LP: #780588
  * Revert "mmc: fix all hangs related to mmc/sd card insert/removal during
    suspend/resume"
    - LP: #780588
  * Revert "econet: fix CVE-2010-3848"
    - LP: #780588
  * Revert "dell-laptop: Add another Dell laptop family to the DMI
    whitelist"
    - LP: #780588
  * Revert "dell-laptop: Add another Dell laptop family to the DMI
    whitelist"
    - LP: #780588
  * Revert "xen: set max_pfn_mapped to the last pfn mapped"
  * cifs: always do is_path_accessible check in cifs_mount
    - LP: #770050
  * video: sn9c102: world-wirtable sysfs files
    - LP: #770050
  * UBIFS: restrict world-writable debugfs files
    - LP: #770050
  * NET: cdc-phonet, handle empty phonet header
    - LP: #770050
  * x86: Fix a bogus unwind annotation in lib/semaphore_32.S
    - LP: #770050
  * tioca: Fix assignment from incompatible pointer warnings
    - LP: #770050
  * mca.c: Fix cast from integer to pointer warning
    - LP: #770050
  * ramfs: fix memleak on no-mmu arch
    - LP: #770050
  * MAINTAINERS: update STABLE BRANCH info
    - LP: #770050
  * UBIFS: fix oops when R/O file-system is fsync'ed
    - LP: #770050
  * x86, cpu: AMD errata checking framework
    - LP: #770050
  * x86, cpu: Clean up AMD erratum 400 workaround
    - LP: #770050
  * x86, AMD: Set ARAT feature on AMD processors
    - LP: #770050
  * x86, amd: Disable GartTlbWlkErr when BIOS forgets it
    - LP: #770050
  * USB: ftdi_sio: Added IDs for CTI USB Serial Devices
    - LP: #770050
  * USB: ftdi_sio: add PID for OCT DK201 docking station
    - LP: #770050
  * USB: ftdi_sio: add ids for Hameg HO720 and HO730
    - LP: #770050
  * USB: option: Add new ONDA vendor id and product id for ONDA MT825UP
    - LP: #770050
  * USB: option: Added support for Samsung GT-B3730/GT-B3710 LTE USB modem.
    - LP: #770050
  * next_pidmap: fix overflow condition
    - LP: #770050
  * proc: do proper range check on readdir offset
    - LP: #770050
  * USB: EHCI: unlink unused QHs when the controller is stopped
    - LP: #770050
  * USB: fix formatting of SuperSpeed endpoints in /proc/bu...

Changed in linux-mvl-dove (Ubuntu Maverick):
status: New → Fix Released
Changed in linux-lts-backport-maverick (Ubuntu Dapper):
status: New → Won't Fix
Changed in linux-lts-backport-maverick (Ubuntu Karmic):
status: New → Won't Fix
Revision history for this message
Jamie Strandboge (jdstrand) wrote :

Thank you for reporting this bug to Ubuntu. maverick has reached EOL
(End of Life) and is no longer supported. As a result, this bug
against maverick is being marked "Won't Fix". Please see
https://wiki.ubuntu.com/Releases for currently supported Ubuntu
releases.

Please feel free to report any other bugs you may find.

Changed in linux-lts-backport-maverick (Ubuntu Maverick):
status: New → Won't Fix
Changed in linux-lts-backport-maverick (Ubuntu Hardy):
status: New → Won't Fix
Changed in linux-lts-backport-maverick (Ubuntu Lucid):
status: New → Won't Fix
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.