Ack: Re: [CVE-2012-0038] ACL overflow oops

Herton Ronaldo Krzesinski herton.krzesinski at canonical.com
Wed Jan 18 13:39:29 UTC 2012


On Wed, Jan 18, 2012 at 11:28:28AM +0000, Andy Whitcroft wrote:
> CVE-2012-0038
> 	integer overflow in the ACL handling code, which could further
> 	lead to heap-based buffer overflow via a crafted filesystem.
> 
> Fixes for this have hit lucid, oneiric and precise via upstream and stable.
> Hardy did not have this code.  Following this email is a set of patches
> for maverick, maverick/ti-omap4, natty and natty/ti-omap4.  These are
> cherry-picks from mainline (though allowing for renames).
> 
> Proposing for maverick, maverick/ti-omap4, natty and natty/ti-omap4.
> 
> -apw
> 
> -- 
> kernel-team mailing list
> kernel-team at lists.ubuntu.com
> https://lists.ubuntu.com/mailman/listinfo/kernel-team
> 




More information about the kernel-team mailing list