Hide Forgot
It was found that a commit which moved certain functionality from btrfs to vfs ioctl introduced a double fetch issue: https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/fs/ioctl.c?h=v4.5&id=54dbc15172375641ef03399e8f911d7165eb90fb This flaw could lead to an undersized allocation and subsequent heap overflow with potentially controlled data. It has been patched in upstream here: https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=10eec60ce79187686e052092e5383c99b4420a20 CVE request: http://seclists.org/oss-sec/2016/q3/213
Created kernel tracking bugs for this issue: Affects: fedora-all [bug 1362458]