Linux kernel built with Direct Rendering Manager(DRM) i915 driver for the the Direct Rendering Infrastructure(DRI) introduced by XFree86 4.0, is vulnerable to a heap overflow flaw. An user/program with access to the DRM driver could use this flaw to crash the kernel, resulting in DoS or possibly escalate privileges. Reference: ---------- -> https://lkml.org/lkml/2013/3/11/501 -> http://www.openwall.com/lists/oss-security/2013/03/11/6
Statement: This issue does not affect the versions of the kernel package as shipped with Red Hat Enterprise Linux 5. This issue affects the version of Linux kernel as shipped with Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG 2. Future kernel updates for Red Hat Enterprise MRG 2 may address this issue.
Upstream fix: ------------- -> https://lkml.org/lkml/2013/3/11/677
Created kernel tracking bugs for this issue Affects: fedora-all [bug 920529]
kernel-3.8.3-201.fc18 has been pushed to the Fedora 18 stable repository. If problems still persist, please make note of it in this bug report.
Other references: http://openwall.com/lists/oss-security/2013/03/13/9 http://openwall.com/lists/oss-security/2013/03/14/22 http://git.chromium.org/gitweb/?p=chromiumos/third_party/kernel.git;a=commit;h=c79efdf2b7f68f985922a8272d64269ecd490477 http://googlechromereleases.blogspot.com/2013/03/stable-channel-update-for-chrome-os_15.html https://code.google.com/p/chromium-os/issues/detail?id=39733 https://gerrit.chromium.org/gerrit/45118
I would rather see git commit in any branch.
kernel-3.8.3-103.fc17 has been pushed to the Fedora 17 stable repository. If problems still persist, please make note of it in this bug report.
Upstream commit: http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=3118a4f652c7b12c752f3222af0447008f9b236
This issue has been addressed in following products: Red Hat Enterprise Linux 6 Via RHSA-2013:0744 https://rhn.redhat.com/errata/RHSA-2013-0744.html
This issue has been addressed in following products: MRG for RHEL-6 v.2 Via RHSA-2013:0829 https://rhn.redhat.com/errata/RHSA-2013-0829.html