Bug 1094240
Summary: | CVE-2014-0196 kernel: pty layer race condition leading memory corruption [fedora-all] | ||
---|---|---|---|
Product: | [Fedora] Fedora | Reporter: | Petr Matousek <pmatouse> |
Component: | kernel | Assignee: | Kernel Maintainer List <kernel-maint> |
Status: | CLOSED ERRATA | QA Contact: | Fedora Extras Quality Assurance <extras-qa> |
Severity: | high | Docs Contact: | |
Priority: | high | ||
Version: | 20 | CC: | davej, gansalmon, itamar, jforbes, jonathan, jwboyer, kernel-maint, madhu.chinakonda, mchehab, opensource |
Target Milestone: | --- | Keywords: | Reopened, Security, SecurityTracking |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | kernel-3.14.4-100.fc19 | Doc Type: | Release Note |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2014-05-21 23:21:41 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | |||
Bug Blocks: | 1094232 |
Description
Petr Matousek
2014-05-05 10:45:31 UTC
Use the following update submission link to create the Bodhi request for this issue as it contains the top-level parent bug(s) as well as this tracking bug. This will ensure that all associated bugs get updated when new packages are pushed to stable. IMPORTANT: ensure that the "Close bugs when update is stable" option remains checked. Bodhi update submission link: https://admin.fedoraproject.org/updates/new/?type_=security&bugs=1094232,1094240 Fixed in Fedora git. F19 should pick this up when we do the 3.14.y rebase. kernel-3.14.3-200.fc20 has been submitted as an update for Fedora 20. https://admin.fedoraproject.org/updates/kernel-3.14.3-200.fc20 Package kernel-3.14.3-200.fc20: * should fix your issue, * was pushed to the Fedora 20 testing repository, * should be available at your local mirror within two days. Update it with: # su -c 'yum update --enablerepo=updates-testing kernel-3.14.3-200.fc20' as soon as you are able to, then reboot. Please go to the following url: https://admin.fedoraproject.org/updates/FEDORA-2014-6122/kernel-3.14.3-200.fc20 then log in and leave karma (feedback). kernel-3.14.3-200.fc20 has been pushed to the Fedora 20 stable repository. If problems still persist, please make note of it in this bug report. Was Fedora 19 updated? All versions of Fedora were affected and I see no mention of F19 at all here. F19 is fixed with the 3.14.3 rebase in updates-testing. Perfect, thank you Josh. (In reply to Josh Boyer from comment #7) > F19 is fixed with the 3.14.3 rebase in updates-testing. Why is this bug not referenced in the update? See: https://admin.fedoraproject.org/updates/FEDORA-2014-6167/kernel-3.14.3-100.fc19 Also it is not in the RPM's changelog according to: http://koji.fedoraproject.org/koji/buildinfo?buildID=515621 The patch is there, as I already explained. kernel-3.14.3-100.fc19 has been submitted as an update for Fedora 19. https://admin.fedoraproject.org/updates/FEDORA-2014-6167/kernel-3.14.3-100.fc19 (In reply to Josh Boyer from comment #10) > The patch is there, as I already explained. Thank you. To communicate this properly to users it should IMHO also be mentioned in the RPM changelog as it is done for the F20 update. We don't list every bug fixed in the RPM changelog. The rebases and stable updates fix entirely too many bugs to list them all out. We can't go back and add it to the changelog of the existing build anyway. kernel-3.14.4-100.fc19 has been submitted as an update for Fedora 19. https://admin.fedoraproject.org/updates/kernel-3.14.4-100.fc19 Package kernel-3.14.4-100.fc19: * should fix your issue, * was pushed to the Fedora 19 testing repository, * should be available at your local mirror within two days. Update it with: # su -c 'yum update --enablerepo=updates-testing kernel-3.14.4-100.fc19' as soon as you are able to, then reboot. Please go to the following url: https://admin.fedoraproject.org/updates/FEDORA-2014-6354/kernel-3.14.4-100.fc19 then log in and leave karma (feedback). kernel-3.14.4-100.fc19 has been pushed to the Fedora 19 stable repository. If problems still persist, please make note of it in this bug report. |