Red Hat Bugzilla – Bug 1481136
CVE-2017-10661 kernel: Handling of might_cancel queueing is not properly pretected against race
Last modified: 2018-10-30 03:37:04 EDT
The handling of the might_cancel queueing is not properly protected, so parallel operations on the file descriptor can race with each other and lead to list corruptions or use after free. References: https://marc.info/?l=linux-fsdevel&m=148587265720603&w=2 https://marc.info/?t=148587273100007&r=1&w=2 https://source.android.com/security/bulletin/2017-08-01#kernel-components Upstream patch: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=1e38da300e1e395a15048b0af1e5305bd91402f6
Statement: This issue does not affect Red Hat Enterprise Linux 5 as the code with the flaw is not present in the products listed. This issue affects Red Hat Enterprise Linux 6, 7 and Red Hat Enterprise MRG 2. Future updates for the respective releases may address this issue.
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2018:3083 https://access.redhat.com/errata/RHSA-2018:3083
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2018:3096 https://access.redhat.com/errata/RHSA-2018:3096