Bug 767914 (CVE-2011-4611) - CVE-2011-4611 kernel: perf, powerpc: Handle events that raise an exception without overflowing
Summary: CVE-2011-4611 kernel: perf, powerpc: Handle events that raise an exception wi...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2011-4611
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard: impact=moderate,public=20110316,repor...
Depends On: 755737 767917 782688 1020604
Blocks: 757776
TreeView+ depends on / blocked
 
Reported: 2011-12-15 08:45 UTC by Eugene Teo (Security Response)
Modified: 2019-06-08 18:59 UTC (History)
17 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2013-08-24 13:55:53 UTC


Attachments (Terms of Use)


Links
System ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2012:0350 normal SHIPPED_LIVE Moderate: kernel security and bug fix update 2012-03-06 23:43:05 UTC

Description Eugene Teo (Security Response) 2011-12-15 08:45:45 UTC
A PMC is 32 bits (ie an int). Since we pass it around as an unsigned long, we need to cast it before doing the comparison.

This does not affect the upstream kernel as it is already fixed. This is an issue that was introduced in bug 720743.

Upstream commit:
http://git.kernel.org/linus/0837e3242c73566fc1c0196b4ec61779c25ffc93

Acknowledgements:

Red Hat would like to thank Maynard Johnson for reporting this issue.

Comment 2 Kurt Seifried 2011-12-15 16:18:30 UTC
Assigned CVE-2011-4611 to this issue http://seclists.org/oss-sec/2011/q4/504

Comment 3 Eugene Teo (Security Response) 2012-01-18 07:14:55 UTC
Created kernel tracking bugs for this issue

Affects: fedora-all [bug 782688]

Comment 6 Eugene Teo (Security Response) 2012-01-29 14:54:55 UTC
Statement:

This issue did not affect the Linux kernels as shipped with Red Hat Enterprise Linux 4 and 5 as they did not have support for Performance event. It did not affect Red Hat Enterprise MRG as it did not provide support for PowerPC. This has been addressed in Red Hat Enterprise Linux 6 via https://rhn.redhat.com/errata/RHSA-2012-0350.html.

Comment 7 errata-xmlrpc 2012-03-06 18:45:22 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 6

Via RHSA-2012:0350 https://rhn.redhat.com/errata/RHSA-2012-0350.html


Note You need to log in before you can comment on or make changes to this bug.