oss-sec mailing list archives

Re: Status of two Linux kernel issues w/o CVE assignments


From: Kurt Seifried <kseifried () redhat com>
Date: Tue, 27 Dec 2011 22:45:55 -0700

My mistake, the /proc/interupts and /proc/stat should be two separate CVE's, I misunderstood the issue.

===========
IIRC, it's an issue but there's no resolution as existing code may break.

There are also,
/proc/{interrupts, stat}
https://lkml.org/lkml/2011/11/7/340

Please use CVE-2011-4915 for the /proc/interupts issue

Please use CVE-2011-4917 for the /proc/stat issue




/dev/pts/, /dev/tty*
https://lkml.org/lkml/2011/11/7/355
Please use CVE-2011-4916 for this issue.



--

-Kurt Seifried / Red Hat Security Response Team


Current thread: