Red Hat Bugzilla – Bug 1308846
CVE-2016-3070 kernel: Null pointer dereference in trace_writeback_dirty_page()
Last modified: 2018-08-28 18:02:32 EDT
It was reported that attempt to move page mapped by aio ring buffer to other node triggers NULL pointer dereference at trace_writeback_dirty_page(), because aio_fs_backing_dev_info.dev is 0. Product bug (contains reproducer): https://bugzilla.redhat.com/show_bug.cgi?id=1306851 Upstream patch: http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=42cb14b110a5698ccf26ce59c4441722605a3743
Acknowledgments: Name: Jan Stancek (Red Hat)
Statement: This issue does not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 5, 6 as the code with the flaw is not present in the products listed. This issue affects the Linux kernel packages as shipped with Red Hat Enterprise Linux 7 and MRG-2. Future updates for the respective releases may address the issue.
Internal CVE assignment: CVE-2016-3070
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2016:2574 https://rhn.redhat.com/errata/RHSA-2016-2574.html
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2016:2584 https://rhn.redhat.com/errata/RHSA-2016-2584.html