Activity log for bug #912221

Date Who What changed Old value New value Message
2012-01-05 12:04:11 John Johansen bug added bug
2012-01-05 12:04:14 John Johansen tags kernel-cve-tracking-bug
2012-01-05 12:04:16 John Johansen security vulnerability no yes
2012-01-05 12:04:16 John Johansen security vulnerability no yes
2012-01-05 12:04:18 John Johansen cve linked 2011-4913
2012-01-05 12:04:29 John Johansen nominated for series Ubuntu Precise
2012-01-05 12:04:30 John Johansen bug task added linux (Ubuntu Precise)
2012-01-05 12:04:30 John Johansen bug task added linux-ec2 (Ubuntu Precise)
2012-01-05 12:04:30 John Johansen bug task added linux-fsl-imx51 (Ubuntu Precise)
2012-01-05 12:04:30 John Johansen bug task added linux-lts-backport-maverick (Ubuntu Precise)
2012-01-05 12:04:30 John Johansen bug task added linux-lts-backport-natty (Ubuntu Precise)
2012-01-05 12:04:30 John Johansen bug task added linux-mvl-dove (Ubuntu Precise)
2012-01-05 12:04:30 John Johansen bug task added linux-ti-omap4 (Ubuntu Precise)
2012-01-05 12:04:38 John Johansen nominated for series Ubuntu Oneiric
2012-01-05 12:04:40 John Johansen bug task added linux (Ubuntu Oneiric)
2012-01-05 12:04:40 John Johansen bug task added linux-ec2 (Ubuntu Oneiric)
2012-01-05 12:04:40 John Johansen bug task added linux-fsl-imx51 (Ubuntu Oneiric)
2012-01-05 12:04:40 John Johansen bug task added linux-lts-backport-maverick (Ubuntu Oneiric)
2012-01-05 12:04:40 John Johansen bug task added linux-lts-backport-natty (Ubuntu Oneiric)
2012-01-05 12:04:40 John Johansen bug task added linux-mvl-dove (Ubuntu Oneiric)
2012-01-05 12:04:40 John Johansen bug task added linux-ti-omap4 (Ubuntu Oneiric)
2012-01-05 12:04:47 John Johansen nominated for series Ubuntu Natty
2012-01-05 12:04:48 John Johansen bug task added linux (Ubuntu Natty)
2012-01-05 12:04:48 John Johansen bug task added linux-ec2 (Ubuntu Natty)
2012-01-05 12:04:48 John Johansen bug task added linux-fsl-imx51 (Ubuntu Natty)
2012-01-05 12:04:48 John Johansen bug task added linux-lts-backport-maverick (Ubuntu Natty)
2012-01-05 12:04:48 John Johansen bug task added linux-lts-backport-natty (Ubuntu Natty)
2012-01-05 12:04:48 John Johansen bug task added linux-mvl-dove (Ubuntu Natty)
2012-01-05 12:04:48 John Johansen bug task added linux-ti-omap4 (Ubuntu Natty)
2012-01-05 12:04:55 John Johansen nominated for series Ubuntu Maverick
2012-01-05 12:04:57 John Johansen bug task added linux (Ubuntu Maverick)
2012-01-05 12:04:57 John Johansen bug task added linux-ec2 (Ubuntu Maverick)
2012-01-05 12:04:57 John Johansen bug task added linux-fsl-imx51 (Ubuntu Maverick)
2012-01-05 12:04:57 John Johansen bug task added linux-lts-backport-maverick (Ubuntu Maverick)
2012-01-05 12:04:57 John Johansen bug task added linux-lts-backport-natty (Ubuntu Maverick)
2012-01-05 12:04:57 John Johansen bug task added linux-mvl-dove (Ubuntu Maverick)
2012-01-05 12:04:57 John Johansen bug task added linux-ti-omap4 (Ubuntu Maverick)
2012-01-05 12:05:04 John Johansen nominated for series Ubuntu Lucid
2012-01-05 12:05:17 John Johansen bug task added linux (Ubuntu Lucid)
2012-01-05 12:05:17 John Johansen bug task added linux-ec2 (Ubuntu Lucid)
2012-01-05 12:05:17 John Johansen bug task added linux-fsl-imx51 (Ubuntu Lucid)
2012-01-05 12:05:17 John Johansen bug task added linux-lts-backport-maverick (Ubuntu Lucid)
2012-01-05 12:05:17 John Johansen bug task added linux-lts-backport-natty (Ubuntu Lucid)
2012-01-05 12:05:17 John Johansen bug task added linux-mvl-dove (Ubuntu Lucid)
2012-01-05 12:05:17 John Johansen bug task added linux-ti-omap4 (Ubuntu Lucid)
2012-01-05 12:05:24 John Johansen nominated for series Ubuntu Hardy
2012-01-05 12:05:26 John Johansen bug task added linux (Ubuntu Hardy)
2012-01-05 12:05:26 John Johansen bug task added linux-ec2 (Ubuntu Hardy)
2012-01-05 12:05:26 John Johansen bug task added linux-fsl-imx51 (Ubuntu Hardy)
2012-01-05 12:05:26 John Johansen bug task added linux-lts-backport-maverick (Ubuntu Hardy)
2012-01-05 12:05:26 John Johansen bug task added linux-lts-backport-natty (Ubuntu Hardy)
2012-01-05 12:05:26 John Johansen bug task added linux-mvl-dove (Ubuntu Hardy)
2012-01-05 12:05:26 John Johansen bug task added linux-ti-omap4 (Ubuntu Hardy)
2012-01-05 12:05:41 John Johansen linux-ec2 (Ubuntu Oneiric): status New Invalid
2012-01-05 12:05:45 John Johansen linux-ec2 (Ubuntu Precise): status New Invalid
2012-01-05 12:05:49 John Johansen linux-ec2 (Ubuntu Hardy): status New Invalid
2012-01-05 12:05:52 John Johansen linux-ec2 (Ubuntu Natty): status New Invalid
2012-01-05 12:05:55 John Johansen linux-lts-backport-oneiric (Ubuntu Oneiric): status New Invalid
2012-01-05 12:05:59 John Johansen linux-lts-backport-oneiric (Ubuntu Precise): status New Invalid
2012-01-05 12:06:01 John Johansen linux-lts-backport-oneiric (Ubuntu Hardy): status New Invalid
2012-01-05 12:06:05 John Johansen linux-lts-backport-oneiric (Ubuntu Maverick): status New Invalid
2012-01-05 12:06:08 John Johansen linux-lts-backport-oneiric (Ubuntu Natty): status New Invalid
2012-01-05 12:06:12 John Johansen linux-lts-backport-natty (Ubuntu Oneiric): status New Invalid
2012-01-05 12:06:16 John Johansen linux-lts-backport-natty (Ubuntu Precise): status New Invalid
2012-01-05 12:06:20 John Johansen linux-lts-backport-natty (Ubuntu Hardy): status New Invalid
2012-01-05 12:06:24 John Johansen linux-lts-backport-natty (Ubuntu Maverick): status New Invalid
2012-01-05 12:06:27 John Johansen linux-lts-backport-natty (Ubuntu Natty): status New Invalid
2012-01-05 12:06:31 John Johansen linux-mvl-dove (Ubuntu Oneiric): status New Invalid
2012-01-05 12:06:33 John Johansen linux-mvl-dove (Ubuntu Precise): status New Invalid
2012-01-05 12:06:38 John Johansen linux-mvl-dove (Ubuntu Hardy): status New Invalid
2012-01-05 12:06:41 John Johansen linux-mvl-dove (Ubuntu Natty): status New Invalid
2012-01-05 12:06:45 John Johansen linux-lts-backport-maverick (Ubuntu Oneiric): status New Invalid
2012-01-05 12:06:48 John Johansen linux-lts-backport-maverick (Ubuntu Precise): status New Invalid
2012-01-05 12:06:52 John Johansen linux-lts-backport-maverick (Ubuntu Hardy): status New Invalid
2012-01-05 12:06:56 John Johansen linux-lts-backport-maverick (Ubuntu Maverick): status New Invalid
2012-01-05 12:06:59 John Johansen linux-lts-backport-maverick (Ubuntu Natty): status New Invalid
2012-01-05 12:07:02 John Johansen linux-ti-omap4 (Ubuntu Lucid): status New Invalid
2012-01-05 12:07:06 John Johansen linux-ti-omap4 (Ubuntu Hardy): status New Invalid
2012-01-05 12:07:10 John Johansen linux-fsl-imx51 (Ubuntu Oneiric): status New Invalid
2012-01-05 12:07:14 John Johansen linux-fsl-imx51 (Ubuntu Precise): status New Invalid
2012-01-05 12:07:16 John Johansen linux-fsl-imx51 (Ubuntu Hardy): status New Invalid
2012-01-05 12:07:19 John Johansen linux-fsl-imx51 (Ubuntu Maverick): status New Invalid
2012-01-05 12:07:22 John Johansen linux-fsl-imx51 (Ubuntu Natty): status New Invalid
2012-01-05 12:07:25 John Johansen description Placeholder When parsing the FAC_CCITT_DEST_NSAP and FAC_CCITT_SRC_NSAP facilities fields, a remote host can provide a length of greater than 20, resulting in a stack overflow of the callsign array. When parsing the FAC_CCITT_DEST_NSAP and FAC_CCITT_SRC_NSAP facilities fields, a remote host can provide a length of less than 10, resulting in an underflow in a memcpy size, causing a kernel panic due to massive heap corruption. Break-Fix: - be20250c13f88375345ad99950190685eda51eb8
2012-01-05 12:07:28 John Johansen linux-ec2 (Ubuntu Oneiric): importance Undecided Medium
2012-01-05 12:07:31 John Johansen linux-ec2 (Ubuntu Lucid): importance Undecided Medium
2012-01-05 12:07:33 John Johansen linux-ec2 (Ubuntu Precise): importance Undecided Medium
2012-01-05 12:07:35 John Johansen linux-ec2 (Ubuntu Hardy): importance Undecided Medium
2012-01-05 12:07:38 John Johansen linux-ec2 (Ubuntu Maverick): status New Invalid
2012-01-05 12:07:40 John Johansen linux-ec2 (Ubuntu Maverick): importance Undecided Medium
2012-01-05 12:07:42 John Johansen linux-ec2 (Ubuntu Natty): importance Undecided Medium
2012-01-05 12:07:45 John Johansen linux-lts-backport-oneiric (Ubuntu Oneiric): importance Undecided Medium
2012-01-05 12:07:48 John Johansen linux-lts-backport-oneiric (Ubuntu Lucid): importance Undecided Medium
2012-01-05 12:07:51 John Johansen linux-lts-backport-oneiric (Ubuntu Precise): importance Undecided Medium
2012-01-05 12:07:54 John Johansen linux-lts-backport-oneiric (Ubuntu Hardy): importance Undecided Medium
2012-01-05 12:07:56 John Johansen linux-lts-backport-oneiric (Ubuntu Maverick): importance Undecided Medium
2012-01-05 12:07:59 John Johansen linux-lts-backport-oneiric (Ubuntu Natty): importance Undecided Medium
2012-01-05 12:08:02 John Johansen linux-lts-backport-natty (Ubuntu Oneiric): importance Undecided Medium
2012-01-05 12:08:05 John Johansen linux-lts-backport-natty (Ubuntu Lucid): importance Undecided Medium
2012-01-05 12:08:08 John Johansen linux-lts-backport-natty (Ubuntu Precise): importance Undecided Medium
2012-01-05 12:08:11 John Johansen linux-lts-backport-natty (Ubuntu Hardy): importance Undecided Medium
2012-01-05 12:08:14 John Johansen linux-lts-backport-natty (Ubuntu Maverick): importance Undecided Medium
2012-01-05 12:08:16 John Johansen linux-lts-backport-natty (Ubuntu Natty): importance Undecided Medium
2012-01-05 12:08:19 John Johansen linux-mvl-dove (Ubuntu Oneiric): importance Undecided Medium
2012-01-05 12:08:22 John Johansen linux-mvl-dove (Ubuntu Lucid): importance Undecided Medium
2012-01-05 12:08:25 John Johansen linux-mvl-dove (Ubuntu Precise): importance Undecided Medium
2012-01-05 12:08:27 John Johansen linux-mvl-dove (Ubuntu Hardy): importance Undecided Medium
2012-01-05 12:08:30 John Johansen linux-mvl-dove (Ubuntu Maverick): importance Undecided Medium
2012-01-05 12:08:33 John Johansen linux-mvl-dove (Ubuntu Natty): importance Undecided Medium
2012-01-05 12:08:36 John Johansen linux-lts-backport-maverick (Ubuntu Oneiric): importance Undecided Medium
2012-01-05 12:08:39 John Johansen linux-lts-backport-maverick (Ubuntu Lucid): importance Undecided Medium
2012-01-05 12:08:42 John Johansen linux-lts-backport-maverick (Ubuntu Precise): importance Undecided Medium
2012-01-05 12:08:45 John Johansen linux-lts-backport-maverick (Ubuntu Hardy): importance Undecided Medium
2012-01-05 12:08:48 John Johansen linux-lts-backport-maverick (Ubuntu Maverick): importance Undecided Medium
2012-01-05 12:08:51 John Johansen linux-lts-backport-maverick (Ubuntu Natty): importance Undecided Medium
2012-01-05 12:08:54 John Johansen linux (Ubuntu Oneiric): importance Undecided Medium
2012-01-05 12:08:56 John Johansen linux (Ubuntu Lucid): importance Undecided Medium
2012-01-05 12:08:59 John Johansen linux (Ubuntu Precise): importance Undecided Medium
2012-01-05 12:09:03 John Johansen linux (Ubuntu Hardy): importance Undecided Medium
2012-01-05 12:09:06 John Johansen linux (Ubuntu Maverick): importance Undecided Medium
2012-01-05 12:09:09 John Johansen linux (Ubuntu Natty): importance Undecided Medium
2012-01-05 12:09:12 John Johansen linux-ti-omap4 (Ubuntu Oneiric): importance Undecided Medium
2012-01-05 12:09:15 John Johansen linux-ti-omap4 (Ubuntu Lucid): importance Undecided Medium
2012-01-05 12:09:18 John Johansen linux-ti-omap4 (Ubuntu Precise): importance Undecided Medium
2012-01-05 12:09:21 John Johansen linux-ti-omap4 (Ubuntu Hardy): importance Undecided Medium
2012-01-05 12:09:24 John Johansen linux-ti-omap4 (Ubuntu Maverick): importance Undecided Medium
2012-01-05 12:09:27 John Johansen linux-ti-omap4 (Ubuntu Natty): importance Undecided Medium
2012-01-05 12:09:29 John Johansen linux-fsl-imx51 (Ubuntu Oneiric): importance Undecided Medium
2012-01-05 12:09:32 John Johansen linux-fsl-imx51 (Ubuntu Lucid): importance Undecided Medium
2012-01-05 12:09:34 John Johansen linux-fsl-imx51 (Ubuntu Precise): importance Undecided Medium
2012-01-05 12:09:37 John Johansen linux-fsl-imx51 (Ubuntu Hardy): importance Undecided Medium
2012-01-05 12:09:40 John Johansen linux-fsl-imx51 (Ubuntu Maverick): importance Undecided Medium
2012-01-05 12:09:43 John Johansen linux-fsl-imx51 (Ubuntu Natty): importance Undecided Medium
2012-01-06 18:47:32 John Johansen linux-ec2 (Ubuntu Lucid): status New Fix Committed
2012-01-06 18:47:36 John Johansen linux-lts-backport-oneiric (Ubuntu Lucid): status New Fix Committed
2012-01-06 18:47:40 John Johansen linux-lts-backport-natty (Ubuntu Lucid): status New Fix Committed
2012-01-06 18:47:43 John Johansen linux-mvl-dove (Ubuntu Lucid): status New Fix Committed
2012-01-06 18:47:48 John Johansen linux-mvl-dove (Ubuntu Maverick): status New Fix Committed
2012-01-06 18:47:51 John Johansen linux-lts-backport-maverick (Ubuntu Lucid): status New Fix Committed
2012-01-06 18:47:55 John Johansen linux (Ubuntu Oneiric): status New Fix Committed
2012-01-06 18:47:59 John Johansen linux (Ubuntu Lucid): status New Fix Committed
2012-01-06 18:48:02 John Johansen linux (Ubuntu Precise): status New Invalid
2012-01-06 18:48:06 John Johansen linux (Ubuntu Hardy): status New Fix Committed
2012-01-06 18:48:10 John Johansen linux (Ubuntu Maverick): status New Fix Committed
2012-01-06 18:48:13 John Johansen linux (Ubuntu Natty): status New Fix Committed
2012-01-06 18:48:16 John Johansen linux-ti-omap4 (Ubuntu Oneiric): status New Fix Committed
2012-01-06 18:48:20 John Johansen linux-ti-omap4 (Ubuntu Precise): status New Invalid
2012-01-06 18:48:24 John Johansen linux-ti-omap4 (Ubuntu Maverick): status New Fix Committed
2012-01-06 18:48:27 John Johansen linux-ti-omap4 (Ubuntu Natty): status New Fix Committed
2012-01-06 18:48:30 John Johansen linux-fsl-imx51 (Ubuntu Lucid): status New Fix Committed
2012-02-03 17:37:02 John Johansen linux-ec2 (Ubuntu Lucid): status Fix Committed Fix Released
2012-02-03 17:37:06 John Johansen linux-mvl-dove (Ubuntu Lucid): status Fix Committed Fix Released
2012-02-03 17:37:12 John Johansen linux-mvl-dove (Ubuntu Maverick): status Fix Committed Fix Released
2012-02-03 17:37:15 John Johansen linux (Ubuntu Lucid): status Fix Committed Fix Released
2012-02-03 17:37:20 John Johansen linux (Ubuntu Hardy): status Fix Committed Fix Released
2012-02-03 17:37:23 John Johansen linux (Ubuntu Maverick): status Fix Committed Fix Released
2012-02-03 17:37:27 John Johansen linux (Ubuntu Natty): status Fix Committed Fix Released
2012-02-03 17:37:31 John Johansen linux-ti-omap4 (Ubuntu Maverick): status Fix Committed Fix Released
2012-02-03 17:37:35 John Johansen linux-ti-omap4 (Ubuntu Natty): status Fix Committed Fix Released
2012-02-03 17:37:38 John Johansen linux-fsl-imx51 (Ubuntu Lucid): status Fix Committed Fix Released
2012-04-17 21:51:41 John Johansen linux-mvl-dove (Ubuntu Maverick): status Fix Released Invalid
2012-04-17 21:51:44 John Johansen linux (Ubuntu Maverick): status Fix Released Invalid
2012-04-17 21:51:47 John Johansen linux-ti-omap4 (Ubuntu Maverick): status Fix Released Invalid
2012-04-17 21:51:52 John Johansen linux-lts-backport-maverick (Ubuntu Lucid): status Fix Committed Fix Released
2012-04-23 19:37:56 John Johansen linux (Ubuntu Maverick): status Invalid Fix Released
2012-04-23 19:38:23 John Johansen linux-mvl-dove (Ubuntu Maverick): status Invalid Fix Released
2012-04-23 19:38:45 John Johansen linux-ti-omap4 (Ubuntu Maverick): status Invalid Fix Released
2012-05-01 02:54:37 John Johansen linux-armadaxp (Ubuntu Maverick): status New Invalid
2012-05-01 20:54:10 John Johansen nominated for series Ubuntu Quantal
2012-05-01 20:54:13 John Johansen linux-armadaxp (Ubuntu Precise): importance Undecided Medium
2012-05-01 20:54:16 John Johansen linux-armadaxp (Ubuntu Oneiric): status New Invalid
2012-05-01 20:54:19 John Johansen linux-armadaxp (Ubuntu Oneiric): importance Undecided Medium
2012-05-01 20:54:23 John Johansen linux-armadaxp (Ubuntu Lucid): status New Invalid
2012-05-01 20:54:27 John Johansen linux-armadaxp (Ubuntu Lucid): importance Undecided Medium
2012-05-01 20:54:31 John Johansen linux-armadaxp (Ubuntu Hardy): status New Invalid
2012-05-01 20:54:34 John Johansen linux-armadaxp (Ubuntu Hardy): importance Undecided Medium
2012-05-01 20:54:36 John Johansen linux-armadaxp (Ubuntu Natty): status New Invalid
2012-05-01 20:54:40 John Johansen linux-armadaxp (Ubuntu Natty): importance Undecided Medium
2012-05-03 20:20:00 John Johansen linux-armadaxp (Ubuntu Precise): status New Fix Committed
2012-05-04 20:45:21 John Johansen bug task added linux (Ubuntu Quantal)
2012-05-04 20:45:21 John Johansen bug task added linux-armadaxp (Ubuntu Quantal)
2012-05-04 20:45:21 John Johansen bug task added linux-ec2 (Ubuntu Quantal)
2012-05-04 20:45:21 John Johansen bug task added linux-fsl-imx51 (Ubuntu Quantal)
2012-05-04 20:45:21 John Johansen bug task added linux-lts-backport-maverick (Ubuntu Quantal)
2012-05-04 20:45:21 John Johansen bug task added linux-lts-backport-natty (Ubuntu Quantal)
2012-05-04 20:45:21 John Johansen bug task added linux-lts-backport-oneiric (Ubuntu Quantal)
2012-05-04 20:45:21 John Johansen bug task added linux-mvl-dove (Ubuntu Quantal)
2012-05-04 20:45:21 John Johansen bug task added linux-ti-omap4 (Ubuntu Quantal)
2012-05-04 22:16:02 John Johansen linux-armadaxp (Ubuntu Quantal): status New Fix Committed
2012-05-04 22:16:05 John Johansen linux-armadaxp (Ubuntu Quantal): importance Undecided Medium
2012-06-29 16:26:56 John Johansen description When parsing the FAC_CCITT_DEST_NSAP and FAC_CCITT_SRC_NSAP facilities fields, a remote host can provide a length of greater than 20, resulting in a stack overflow of the callsign array. When parsing the FAC_CCITT_DEST_NSAP and FAC_CCITT_SRC_NSAP facilities fields, a remote host can provide a length of less than 10, resulting in an underflow in a memcpy size, causing a kernel panic due to massive heap corruption. Break-Fix: - be20250c13f88375345ad99950190685eda51eb8 The rose_parse_ccitt function in net/rose/rose_subr.c in the Linux kernel before 2.6.39 does not validate the FAC_CCITT_DEST_NSAP and FAC_CCITT_SRC_NSAP fields, which allows remote attackers to (1) cause a denial of service (integer underflow, heap memory corruption, and panic) via a small length value in data sent to a ROSE socket, or (2) conduct stack-based buffer overflow attacks via a large length value in data sent to a ROSE socket. Break-Fix: - be20250c13f88375345ad99950190685eda51eb8
2012-09-20 04:18:14 Ike Panhc linux-armadaxp (Ubuntu Precise): status Fix Committed Fix Released
2012-09-20 04:18:34 Ike Panhc linux-armadaxp (Ubuntu Quantal): status Fix Committed Fix Released
2013-05-21 21:37:47 Jamie Strandboge linux-lts-backport-oneiric (Ubuntu Lucid): status Fix Committed Won't Fix
2013-05-21 21:37:56 Jamie Strandboge linux-ti-omap4 (Ubuntu Oneiric): status Fix Committed Won't Fix
2013-05-22 12:23:28 Jamie Strandboge linux-lts-backport-natty (Ubuntu Lucid): status Fix Committed Won't Fix
2013-07-12 20:09:53 Jamie Strandboge linux (Ubuntu Oneiric): status Fix Committed Won't Fix