Bug 127918 - CAN-2004-0685 usb sparse fixes in 2.4
Summary: CAN-2004-0685 usb sparse fixes in 2.4
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Red Hat Enterprise Linux 3
Classification: Red Hat
Component: kernel
Version: 3.0
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Pete Zaitcev
QA Contact: Brian Brock
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2004-07-15 11:57 UTC by Mark J. Cox
Modified: 2007-11-30 22:07 UTC (History)
5 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2004-12-02 11:37:19 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)
updated USB driver data leak patch (1.15 KB, patch)
2004-08-31 23:00 UTC, Ernie Petrides
no flags Details | Diff


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2004:549 0 normal SHIPPED_LIVE Important: kernel security update 2004-12-02 05:00:00 UTC

Description Mark J. Cox 2004-07-15 11:57:03 UTC
Back in October 2003 Arnaldo commited some fixes prior to 2.6 for some
leaking info to userspace in the usb drivers:
http://linux.bkbits.net:8080/linux-2.6/cset@3f986b35LyBKc-OxB8G6k22oOjgYTQ

The corresponding changes have not been commited to 2.4, or included in
the previous sparse fixes.  So I've assigned them CAN-2004-0685 (for 2.4
only, as they were fixed before 2.6.0).   Treat as public.

Comment 1 Mark J. Cox 2004-07-28 10:40:55 UTC
Now fixed upstream, see
http://linux.bkbits.net:8080/linux-2.4/cset@410582380U3H9KOx8J2YZmMT0bhXQw

Comment 2 Ernie Petrides 2004-08-31 23:00:30 UTC
Created attachment 103320 [details]
updated USB driver data leak patch

Pete, I'll take care of this in the next U4 build, since Mark
was kind enough to post a patch to rhkernel-list (15-Jul-2004).
Mark, I'm dropping 2 of the original patch hunks because they
are unnecessary (in view of the strncpy() fixes made in U2),
and I've tweaked the remaining 3 hunks to zero only the
unassigned data fields.

Comment 3 Ernie Petrides 2004-09-02 02:46:07 UTC
The changes in comment #2 have just been committed to the RHEL3 U4
patch pool this evening (in kernel version 2.4.21-20.2.EL).


Comment 4 Ernie Petrides 2004-11-25 01:22:18 UTC
The fix for this problem has also been committed to the RHEL3 E4
patch pool this evening (in kernel version 2.4.21-20.0.1.EL).


Comment 5 Mark J. Cox 2004-12-02 11:37:19 UTC
http://rhn.redhat.com/errata/RHSA-2004-549.html


Note You need to log in before you can comment on or make changes to this bug.