Ubuntu

CVE-2010-4263

Reported by Leann Ogasawara on 2011-03-17
258
This bug affects 1 person
Affects Status Importance Assigned to Milestone
linux (Ubuntu)
Undecided
Unassigned
Dapper
Undecided
Unassigned
Hardy
Undecided
Unassigned
Karmic
Undecided
Unassigned
Lucid
Medium
Leann Ogasawara
Maverick
Undecided
Unassigned
Natty
Undecided
Unassigned
linux-fsl-imx51 (Ubuntu)
Undecided
Unassigned
Dapper
Undecided
Unassigned
Hardy
Undecided
Unassigned
Karmic
Undecided
Unassigned
Lucid
Undecided
Unassigned
Maverick
Undecided
Unassigned
Natty
Undecided
Unassigned
linux-lts-backport-maverick (Ubuntu)
Undecided
Unassigned
Dapper
Undecided
Unassigned
Hardy
Undecided
Unassigned
Karmic
Undecided
Unassigned
Lucid
Undecided
Unassigned
Maverick
Undecided
Unassigned
Natty
Undecided
Unassigned
linux-mvl-dove (Ubuntu)
Undecided
Unassigned
Dapper
Undecided
Unassigned
Hardy
Undecided
Unassigned
Karmic
Undecided
Unassigned
Lucid
Undecided
Paolo Pisati
Maverick
Undecided
Paolo Pisati
Natty
Undecided
Unassigned
linux-ti-omap4 (Ubuntu)
Undecided
Unassigned
Dapper
Undecided
Unassigned
Hardy
Undecided
Unassigned
Karmic
Undecided
Unassigned
Lucid
Undecided
Unassigned
Maverick
Undecided
Unassigned
Natty
Undecided
Unassigned

Bug Description

The igb_receive_skb function in drivers/net/igb/igb_main.c in the Intel
Gigabit Ethernet (aka igb) subsystem in the Linux kernel before 2.6.34,
when Single Root I/O Virtualization (SR-IOV) and promiscuous mode are
enabled but no VLANs are registered, allows remote attackers to cause a
denial of service (NULL pointer dereference and panic) and possibly have
unspecified other impact via a VLAN tagged frame.

security vulnerability: no → yes
description: updated
Changed in linux (Ubuntu Dapper):
status: New → Invalid
Changed in linux (Ubuntu Hardy):
status: New → Invalid
Changed in linux (Ubuntu Karmic):
status: New → Invalid
Changed in linux (Ubuntu Lucid):
assignee: nobody → Leann Ogasawara (leannogasawara)
importance: Undecided → Medium
status: New → In Progress
Changed in linux (Ubuntu Maverick):
status: New → Invalid
Changed in linux (Ubuntu Natty):
status: New → Invalid
Tim Gardner (timg-tpi) on 2011-03-18
Changed in linux (Ubuntu Lucid):
status: In Progress → Fix Committed
Changed in linux-mvl-dove (Ubuntu Natty):
status: New → Invalid
Changed in linux-lts-backport-maverick (Ubuntu Natty):
status: New → Invalid
Changed in linux-fsl-imx51 (Ubuntu Natty):
status: New → Invalid
Paolo Pisati (p-pisati) on 2011-03-24
Changed in linux-ti-omap4 (Ubuntu Maverick):
status: New → Invalid
Changed in linux-ti-omap4 (Ubuntu Lucid):
status: New → Invalid
Changed in linux-ti-omap4 (Ubuntu Karmic):
status: New → Invalid
Changed in linux-ti-omap4 (Ubuntu Hardy):
status: New → Invalid
Changed in linux-ti-omap4 (Ubuntu Dapper):
status: New → Invalid
Changed in linux-ti-omap4 (Ubuntu Natty):
status: New → Invalid
Paolo Pisati (p-pisati) on 2011-03-24
Changed in linux-mvl-dove (Ubuntu Dapper):
status: New → Invalid
Changed in linux-mvl-dove (Ubuntu Hardy):
status: New → Invalid
Changed in linux-mvl-dove (Ubuntu Karmic):
status: New → Invalid
Changed in linux-mvl-dove (Ubuntu Maverick):
assignee: nobody → Paolo Pisati (p-pisati)
Changed in linux-mvl-dove (Ubuntu Natty):
assignee: nobody → Paolo Pisati (p-pisati)
assignee: Paolo Pisati (p-pisati) → nobody
Changed in linux-mvl-dove (Ubuntu Lucid):
assignee: nobody → Paolo Pisati (p-pisati)
Brad Figg (brad-figg) on 2011-04-25
tags: added: kernel-cve-tracking-bug
Paolo Pisati (p-pisati) on 2011-04-28
Changed in linux (Ubuntu Lucid):
status: Fix Committed → Fix Released
Paolo Pisati (p-pisati) on 2011-04-29
Changed in linux-mvl-dove (Ubuntu Lucid):
status: New → In Progress
Paolo Pisati (p-pisati) wrote :

karmic is EOL

Changed in linux-fsl-imx51 (Ubuntu Dapper):
status: New → Invalid
Changed in linux-fsl-imx51 (Ubuntu Hardy):
status: New → Invalid
Changed in linux-fsl-imx51 (Ubuntu Maverick):
status: New → Invalid
Changed in linux-fsl-imx51 (Ubuntu Karmic):
status: New → Won't Fix
Paolo Pisati (p-pisati) wrote :

in igb_receive_skb() we already check if vlans are registered to this adapter: no need for this fix.

Changed in linux-fsl-imx51 (Ubuntu Lucid):
status: New → Invalid
Paolo Pisati (p-pisati) wrote :

in igb_receive_skb() we already check for the vlan to be attached to the NIC: no need for this fix.

Launchpad Janitor (janitor) wrote :
Download full text (29.1 KiB)

This bug was fixed in the package linux-mvl-dove - 2.6.32-217.34

---------------
linux-mvl-dove (2.6.32-217.34) lucid-proposed; urgency=low

  [ Herton R. Krzesinski ]

  * Release Tracking Bug
    - LP: #794695

  [ Paolo Pisati ]

  * Rebased to 2.6.32-33.66

  [ Ubuntu: 2.6.32-33.66 ]

  * Release Tracking Bug
    - LP: #794098
  * Revert "xhci: Fix full speed bInterval encoding."
  * Revert "USB: xhci - fix math in xhci_get_endpoint_interval()"
  * Revert "USB: xhci - fix unsafe macro definitions"

  [ Ubuntu: 2.6.32-33.65 ]

  * xhci: Fix full speed bInterval encoding.
    - LP: #792959

  [ Ubuntu: 2.6.32-33.64 ]

   * Release Tracking Bug
     - LP: #789325
  * SAUCE: (no-up) Fix up KVM: VMX: Fix host userspace gsbase corruption
    - LP: #787675
  * SAUCE: vesafb: mtrr module parameter is uint, not bool
    - LP: #778043
  * Revert "(pre-stable): input: Support Clickpad devices in ClickZone
    mode"
    - LP: #780588
  * Revert "GFS2: Fix writing to non-page aligned gfs2_quota structures"
    - LP: #780588
  * Revert "mmc: build fix: mmc_pm_notify is only available with
    CONFIG_PM=y"
    - LP: #780588
  * Revert "mmc: fix all hangs related to mmc/sd card insert/removal during
    suspend/resume"
    - LP: #780588
  * Revert "econet: fix CVE-2010-3848"
    - LP: #780588
  * Revert "dell-laptop: Add another Dell laptop family to the DMI
    whitelist"
    - LP: #780588
  * Revert "dell-laptop: Add another Dell laptop family to the DMI
    whitelist"
    - LP: #780588
  * Revert "xen: set max_pfn_mapped to the last pfn mapped"
  * cifs: always do is_path_accessible check in cifs_mount
    - LP: #770050
  * video: sn9c102: world-wirtable sysfs files
    - LP: #770050
  * UBIFS: restrict world-writable debugfs files
    - LP: #770050
  * NET: cdc-phonet, handle empty phonet header
    - LP: #770050
  * x86: Fix a bogus unwind annotation in lib/semaphore_32.S
    - LP: #770050
  * tioca: Fix assignment from incompatible pointer warnings
    - LP: #770050
  * mca.c: Fix cast from integer to pointer warning
    - LP: #770050
  * ramfs: fix memleak on no-mmu arch
    - LP: #770050
  * MAINTAINERS: update STABLE BRANCH info
    - LP: #770050
  * UBIFS: fix oops when R/O file-system is fsync'ed
    - LP: #770050
  * x86, cpu: AMD errata checking framework
    - LP: #770050
  * x86, cpu: Clean up AMD erratum 400 workaround
    - LP: #770050
  * x86, AMD: Set ARAT feature on AMD processors
    - LP: #770050
  * x86, amd: Disable GartTlbWlkErr when BIOS forgets it
    - LP: #770050
  * USB: ftdi_sio: Added IDs for CTI USB Serial Devices
    - LP: #770050
  * USB: ftdi_sio: add PID for OCT DK201 docking station
    - LP: #770050
  * USB: ftdi_sio: add ids for Hameg HO720 and HO730
    - LP: #770050
  * USB: option: Add new ONDA vendor id and product id for ONDA MT825UP
    - LP: #770050
  * USB: option: Added support for Samsung GT-B3730/GT-B3710 LTE USB modem.
    - LP: #770050
  * next_pidmap: fix overflow condition
    - LP: #770050
  * proc: do proper range check on readdir offset
    - LP: #770050
  * USB: EHCI: unlink unused QHs when the controller is stopped
    - LP: #770050
  * USB: fix formatting of SuperSpeed endpoints in /proc/bus/u...

Changed in linux-mvl-dove (Ubuntu Lucid):
status: In Progress → Fix Released
Launchpad Janitor (janitor) wrote :
Download full text (29.1 KiB)

This bug was fixed in the package linux-mvl-dove - 2.6.32-417.34

---------------
linux-mvl-dove (2.6.32-417.34) maverick-proposed; urgency=low

  [ Herton R. Krzesinski ]

  * Release Tracking Bug
    - LP: #795153

  [ Paolo Pisati ]

  * Rebased to 2.6.32-33.66

  [ Ubuntu: 2.6.32-33.66 ]

  * Release Tracking Bug
    - LP: #794098
  * Revert "xhci: Fix full speed bInterval encoding."
  * Revert "USB: xhci - fix math in xhci_get_endpoint_interval()"
  * Revert "USB: xhci - fix unsafe macro definitions"

  [ Ubuntu: 2.6.32-33.65 ]

  * xhci: Fix full speed bInterval encoding.
    - LP: #792959

  [ Ubuntu: 2.6.32-33.64 ]

   * Release Tracking Bug
     - LP: #789325
  * SAUCE: (no-up) Fix up KVM: VMX: Fix host userspace gsbase corruption
    - LP: #787675
  * SAUCE: vesafb: mtrr module parameter is uint, not bool
    - LP: #778043
  * Revert "(pre-stable): input: Support Clickpad devices in ClickZone
    mode"
    - LP: #780588
  * Revert "GFS2: Fix writing to non-page aligned gfs2_quota structures"
    - LP: #780588
  * Revert "mmc: build fix: mmc_pm_notify is only available with
    CONFIG_PM=y"
    - LP: #780588
  * Revert "mmc: fix all hangs related to mmc/sd card insert/removal during
    suspend/resume"
    - LP: #780588
  * Revert "econet: fix CVE-2010-3848"
    - LP: #780588
  * Revert "dell-laptop: Add another Dell laptop family to the DMI
    whitelist"
    - LP: #780588
  * Revert "dell-laptop: Add another Dell laptop family to the DMI
    whitelist"
    - LP: #780588
  * Revert "xen: set max_pfn_mapped to the last pfn mapped"
  * cifs: always do is_path_accessible check in cifs_mount
    - LP: #770050
  * video: sn9c102: world-wirtable sysfs files
    - LP: #770050
  * UBIFS: restrict world-writable debugfs files
    - LP: #770050
  * NET: cdc-phonet, handle empty phonet header
    - LP: #770050
  * x86: Fix a bogus unwind annotation in lib/semaphore_32.S
    - LP: #770050
  * tioca: Fix assignment from incompatible pointer warnings
    - LP: #770050
  * mca.c: Fix cast from integer to pointer warning
    - LP: #770050
  * ramfs: fix memleak on no-mmu arch
    - LP: #770050
  * MAINTAINERS: update STABLE BRANCH info
    - LP: #770050
  * UBIFS: fix oops when R/O file-system is fsync'ed
    - LP: #770050
  * x86, cpu: AMD errata checking framework
    - LP: #770050
  * x86, cpu: Clean up AMD erratum 400 workaround
    - LP: #770050
  * x86, AMD: Set ARAT feature on AMD processors
    - LP: #770050
  * x86, amd: Disable GartTlbWlkErr when BIOS forgets it
    - LP: #770050
  * USB: ftdi_sio: Added IDs for CTI USB Serial Devices
    - LP: #770050
  * USB: ftdi_sio: add PID for OCT DK201 docking station
    - LP: #770050
  * USB: ftdi_sio: add ids for Hameg HO720 and HO730
    - LP: #770050
  * USB: option: Add new ONDA vendor id and product id for ONDA MT825UP
    - LP: #770050
  * USB: option: Added support for Samsung GT-B3730/GT-B3710 LTE USB modem.
    - LP: #770050
  * next_pidmap: fix overflow condition
    - LP: #770050
  * proc: do proper range check on readdir offset
    - LP: #770050
  * USB: EHCI: unlink unused QHs when the controller is stopped
    - LP: #770050
  * USB: fix formatting of SuperSpeed endpoints in /proc/bu...

Changed in linux-mvl-dove (Ubuntu Maverick):
status: New → Fix Released
Changed in linux-lts-backport-maverick (Ubuntu Dapper):
status: New → Won't Fix
Changed in linux-lts-backport-maverick (Ubuntu Karmic):
status: New → Won't Fix
Jamie Strandboge (jdstrand) wrote :

Thank you for reporting this bug to Ubuntu. maverick has reached EOL
(End of Life) and is no longer supported. As a result, this bug
against maverick is being marked "Won't Fix". Please see
https://wiki.ubuntu.com/Releases for currently supported Ubuntu
releases.

Please feel free to report any other bugs you may find.

Changed in linux-lts-backport-maverick (Ubuntu Maverick):
status: New → Won't Fix
Changed in linux-lts-backport-maverick (Ubuntu Hardy):
status: New → Won't Fix
Changed in linux-lts-backport-maverick (Ubuntu Lucid):
status: New → Won't Fix
To post a comment you must log in.
This report contains Public Security information  Edit
Everyone can see this security related information.

Other bug subscribers