Bug 2061454
| Summary: | CVE-2022-0847 kernel: improper initialization of the "flags" member of the new pipe_buffer [fedora-all] | ||
|---|---|---|---|
| Product: | [Fedora] Fedora | Reporter: | Marian Rehak <mrehak> |
| Component: | kernel | Assignee: | Kernel Maintainer List <kernel-maint> |
| Status: | CLOSED ERRATA | QA Contact: | Fedora Extras Quality Assurance <extras-qa> |
| Severity: | high | Docs Contact: | |
| Priority: | urgent | ||
| Version: | 35 | CC: | acaringi, adscvr, airlied, alciregi, berend, bskeggs, dustymabe, graham, hdegoede, jarodwilson, jeremy, jforbes, jglisse, jonathan, josef, jwboyer, kernel-maint, lgoncalv, linville, masami256, mchehab, ptalbert, steved, tim, troels, trondham, zulinx86 |
| Target Milestone: | --- | Keywords: | Security, SecurityTracking |
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | No Doc Update | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2022-03-08 16:21:41 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | |||
| Bug Blocks: | 2060795 | ||
|
Description
Marian Rehak
2022-03-07 15:43:08 UTC
Use the following template to for the 'fedpkg update' request to submit an update for this issue as it contains the top-level parent bug(s) as well as this tracking bug. This will ensure that all associated bugs get updated when new packages are pushed to stable. ===== # bugfix, security, enhancement, newpackage (required) type=security # low, medium, high, urgent (required) severity=high # testing, stable request=testing # Bug numbers: 1234,9876 bugs=2060795,2061454 # Description of your update notes=Security fix for [PUT CVEs HERE] # Enable request automation based on the stable/unstable karma thresholds autokarma=True stable_karma=3 unstable_karma=-3 # Automatically close bugs when this marked as stable close_bugs=True # Suggest that users restart after update suggest_reboot=False ====== Additionally, you may opt to use the bodhi web interface to submit updates: https://bodhi.fedoraproject.org/updates/new Fedora already picked up the 5.16.11 kernel in https://bodhi.fedoraproject.org/updates/FEDORA-2022-edbd74424e 12 days ago. But the tracking BZ ticket or the CVE reference of CVE-2022-0847 isn't mentioned in the list of bugs or the SPEC files changelog. This was fixed for Fedora in the 5.16.11 stable kernel update. (In reply to Graham Williamson from comment #2) > Fedora already picked up the 5.16.11 kernel in > https://bodhi.fedoraproject.org/updates/FEDORA-2022-edbd74424e 12 days ago. > But the tracking BZ ticket or the CVE reference of CVE-2022-0847 isn't > mentioned in the list of bugs or the SPEC files changelog. This frequently happens with Fedora, where fixes are not marked as security and assigned a CVE until after a kernel update is filed and released. Sometimes issues are embargoed, but the patch is public, so updates get pushed out without relevant security annotation. |