DescriptionEugene Teo (Security Response)
2009-08-19 04:43:33 UTC
Description of problem:
It is possible to modify one of the md/ sysfs files - suspend_lo or suspend_hi when the array is not active. NOTE: this is only a vulnerability when sysfs files are writable by an attacker. It is not writable by default.
This was introduced in commit e464eafd (v2.6.17-rc1).
Upstream commit:
http://git.kernel.org/linus/b8d966efd9a46a9a35beac50cbff6e30565125ef
Comment 2Fedora Update System
2009-08-26 05:12:13 UTC
Comment 3Fedora Update System
2009-08-27 02:19:01 UTC
kernel-2.6.29.6-217.2.16.fc11 has been pushed to the Fedora 11 stable repository. If problems still persist, please make note of it in this bug report.