linux-media.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* Backport a Security Fix for CVE-2015-7833 to v4.1
@ 2016-04-11  5:19 Yuki Machida
  2016-04-11 12:03 ` Vladis Dronov
  0 siblings, 1 reply; 11+ messages in thread
From: Yuki Machida @ 2016-04-11  5:19 UTC (permalink / raw)
  To: sasha.levin
  Cc: linux-media, stable, hverkuil, oneukum, vdronov, mchehab, ralf

Hi Sasha,

I conformed that these patches for CVE-2015-7833 not applied at v4.1.21.
588afcc1c0e45358159090d95bf7b246fb67565
fa52bd506f274b7619955917abfde355e3d19ff
Could you please apply this CVE-2015-7833 fix for 4.1-stable ?

References:
https://security-tracker.debian.org/tracker/CVE-2015-7833
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=588afcc1c0e45358159090d95bf7b246fb67565f
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=fa52bd506f274b7619955917abfde355e3d19ffe

Regards,
Yuki Machida

^ permalink raw reply	[flat|nested] 11+ messages in thread

* Re: Backport a Security Fix for CVE-2015-7833 to v4.1
  2016-04-11  5:19 Backport a Security Fix for CVE-2015-7833 to v4.1 Yuki Machida
@ 2016-04-11 12:03 ` Vladis Dronov
  2016-04-15  8:31   ` Yuki Machida
  2016-04-15  8:49   ` Hans Verkuil
  0 siblings, 2 replies; 11+ messages in thread
From: Vladis Dronov @ 2016-04-11 12:03 UTC (permalink / raw)
  To: Yuki Machida
  Cc: sasha levin, linux-media, stable, hverkuil, oneukum, mchehab, ralf

Hello,

I apologize for intercepting, but I believe commit 588afcc1 should
not be accepted and reverted in the trees where it was.

Reasons:

https://patchwork.linuxtv.org/patch/32798/
or
https://www.spinics.net/lists/linux-media/msg96936.html


Best regards,
Vladis Dronov | Red Hat, Inc. | Product Security Engineer

----- Original Message -----
From: "Yuki Machida" <machida.yuki@jp.fujitsu.com>
To: "sasha levin" <sasha.levin@oracle.com>
Cc: linux-media@vger.kernel.org, stable@vger.kernel.org, hverkuil@xs4all.nl, oneukum@suse.com, vdronov@redhat.com, mchehab@osg.samsung.com, ralf@spenneberg.net
Sent: Monday, April 11, 2016 7:19:34 AM
Subject: Backport a Security Fix for CVE-2015-7833 to v4.1

Hi Sasha,

I conformed that these patches for CVE-2015-7833 not applied at v4.1.21.
588afcc1c0e45358159090d95bf7b246fb67565
fa52bd506f274b7619955917abfde355e3d19ff
Could you please apply this CVE-2015-7833 fix for 4.1-stable ?

References:
https://security-tracker.debian.org/tracker/CVE-2015-7833
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=588afcc1c0e45358159090d95bf7b246fb67565f
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=fa52bd506f274b7619955917abfde355e3d19ffe

Regards,
Yuki Machida

^ permalink raw reply	[flat|nested] 11+ messages in thread

* Re: Backport a Security Fix for CVE-2015-7833 to v4.1
  2016-04-11 12:03 ` Vladis Dronov
@ 2016-04-15  8:31   ` Yuki Machida
  2016-04-15  9:55     ` Vladis Dronov
  2016-04-15  8:49   ` Hans Verkuil
  1 sibling, 1 reply; 11+ messages in thread
From: Yuki Machida @ 2016-04-15  8:31 UTC (permalink / raw)
  To: Vladis Dronov
  Cc: sasha levin, linux-media, stable, hverkuil, oneukum, mchehab, ralf

Hi Vladis,

 > I apologize for intercepting, but I believe commit 588afcc1 should
 > not be accepted and reverted in the trees where it was.
 >
 > Reasons:
 >
 > https://patchwork.linuxtv.org/patch/32798/
 > or
 > https://www.spinics.net/lists/linux-media/msg96936.html
Thank you for your reply.

If it revert commit 588afcc1 from the kernel,
It exists a Security Issue of CVE-2015-7833.
What do you think about it?

Best regards,
Yuki Machida

On 2016年04月11日 21:03, Vladis Dronov wrote:
> Hello,
>
> I apologize for intercepting, but I believe commit 588afcc1 should
> not be accepted and reverted in the trees where it was.
>
> Reasons:
>
> https://patchwork.linuxtv.org/patch/32798/
> or
> https://www.spinics.net/lists/linux-media/msg96936.html
>
>
> Best regards,
> Vladis Dronov | Red Hat, Inc. | Product Security Engineer
>
> ----- Original Message -----
> From: "Yuki Machida" <machida.yuki@jp.fujitsu.com>
> To: "sasha levin" <sasha.levin@oracle.com>
> Cc: linux-media@vger.kernel.org, stable@vger.kernel.org, hverkuil@xs4all.nl, oneukum@suse.com, vdronov@redhat.com, mchehab@osg.samsung.com, ralf@spenneberg.net
> Sent: Monday, April 11, 2016 7:19:34 AM
> Subject: Backport a Security Fix for CVE-2015-7833 to v4.1
>
> Hi Sasha,
>
> I conformed that these patches for CVE-2015-7833 not applied at v4.1.21.
> 588afcc1c0e45358159090d95bf7b246fb67565
> fa52bd506f274b7619955917abfde355e3d19ff
> Could you please apply this CVE-2015-7833 fix for 4.1-stable ?
>
> References:
> https://security-tracker.debian.org/tracker/CVE-2015-7833
> https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=588afcc1c0e45358159090d95bf7b246fb67565f
> https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=fa52bd506f274b7619955917abfde355e3d19ffe
>
> Regards,
> Yuki Machida
>

^ permalink raw reply	[flat|nested] 11+ messages in thread

* Re: Backport a Security Fix for CVE-2015-7833 to v4.1
  2016-04-11 12:03 ` Vladis Dronov
  2016-04-15  8:31   ` Yuki Machida
@ 2016-04-15  8:49   ` Hans Verkuil
  2016-04-15  9:57     ` Vladis Dronov
  1 sibling, 1 reply; 11+ messages in thread
From: Hans Verkuil @ 2016-04-15  8:49 UTC (permalink / raw)
  To: Vladis Dronov, Yuki Machida
  Cc: sasha levin, linux-media, stable, oneukum, mchehab, ralf

Hi Vladis,

On 04/11/2016 02:03 PM, Vladis Dronov wrote:
> Hello,
> 
> I apologize for intercepting, but I believe commit 588afcc1 should
> not be accepted and reverted in the trees where it was.

Your patch requesting that commit to be reverted fell through the cracks.

Having looked at it I agree that it should be reverted and I will apply it.

The main reason is really the incorrect error return which should have been
a goto. But as you say reverting it is easiest since your code does the
right thing.

Regards,

	Hans

> 
> Reasons:
> 
> https://patchwork.linuxtv.org/patch/32798/
> or
> https://www.spinics.net/lists/linux-media/msg96936.html
> 
> 
> Best regards,
> Vladis Dronov | Red Hat, Inc. | Product Security Engineer
> 
> ----- Original Message -----
> From: "Yuki Machida" <machida.yuki@jp.fujitsu.com>
> To: "sasha levin" <sasha.levin@oracle.com>
> Cc: linux-media@vger.kernel.org, stable@vger.kernel.org, hverkuil@xs4all.nl, oneukum@suse.com, vdronov@redhat.com, mchehab@osg.samsung.com, ralf@spenneberg.net
> Sent: Monday, April 11, 2016 7:19:34 AM
> Subject: Backport a Security Fix for CVE-2015-7833 to v4.1
> 
> Hi Sasha,
> 
> I conformed that these patches for CVE-2015-7833 not applied at v4.1.21.
> 588afcc1c0e45358159090d95bf7b246fb67565
> fa52bd506f274b7619955917abfde355e3d19ff
> Could you please apply this CVE-2015-7833 fix for 4.1-stable ?
> 
> References:
> https://security-tracker.debian.org/tracker/CVE-2015-7833
> https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=588afcc1c0e45358159090d95bf7b246fb67565f
> https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=fa52bd506f274b7619955917abfde355e3d19ffe
> 
> Regards,
> Yuki Machida
> --
> To unsubscribe from this list: send the line "unsubscribe linux-media" in
> the body of a message to majordomo@vger.kernel.org
> More majordomo info at  http://vger.kernel.org/majordomo-info.html
> 


^ permalink raw reply	[flat|nested] 11+ messages in thread

* Re: Backport a Security Fix for CVE-2015-7833 to v4.1
  2016-04-15  8:31   ` Yuki Machida
@ 2016-04-15  9:55     ` Vladis Dronov
  2016-04-18  8:32       ` Yuki Machida
  2016-04-18  9:01       ` Yuki Machida
  0 siblings, 2 replies; 11+ messages in thread
From: Vladis Dronov @ 2016-04-15  9:55 UTC (permalink / raw)
  To: Yuki Machida
  Cc: sasha levin, linux-media, stable, hverkuil, oneukum, mchehab, ralf

Hello, Yuki, all,

My commit fa52bd506f resolves CVE-2015-7833, as mentioned in
https://www.spinics.net/lists/linux-media/msg96936.html

Please, note a message from Hans down this thread, who agrees
with my point.

Best regards,
Vladis Dronov | Red Hat, Inc. | Product Security Engineer

----- Original Message -----
From: "Yuki Machida" <machida.yuki@jp.fujitsu.com>
To: "Vladis Dronov" <vdronov@redhat.com>
Cc: "sasha levin" <sasha.levin@oracle.com>, linux-media@vger.kernel.org, stable@vger.kernel.org, hverkuil@xs4all.nl, oneukum@suse.com, mchehab@osg.samsung.com, ralf@spenneberg.net
Sent: Friday, April 15, 2016 10:31:17 AM
Subject: Re: Backport a Security Fix for CVE-2015-7833 to v4.1

Hi Vladis,

 > I apologize for intercepting, but I believe commit 588afcc1 should
 > not be accepted and reverted in the trees where it was.
 >
 > Reasons:
 >
 > https://patchwork.linuxtv.org/patch/32798/
 > or
 > https://www.spinics.net/lists/linux-media/msg96936.html
Thank you for your reply.

If it revert commit 588afcc1 from the kernel,
It exists a Security Issue of CVE-2015-7833.
What do you think about it?

Best regards,
Yuki Machida

On 2016年04月11日 21:03, Vladis Dronov wrote:
> Hello,
>
> I apologize for intercepting, but I believe commit 588afcc1 should
> not be accepted and reverted in the trees where it was.
>
> Reasons:
>
> https://patchwork.linuxtv.org/patch/32798/
> or
> https://www.spinics.net/lists/linux-media/msg96936.html
>
>
> Best regards,
> Vladis Dronov | Red Hat, Inc. | Product Security Engineer
>
> ----- Original Message -----
> From: "Yuki Machida" <machida.yuki@jp.fujitsu.com>
> To: "sasha levin" <sasha.levin@oracle.com>
> Cc: linux-media@vger.kernel.org, stable@vger.kernel.org, hverkuil@xs4all.nl, oneukum@suse.com, vdronov@redhat.com, mchehab@osg.samsung.com, ralf@spenneberg.net
> Sent: Monday, April 11, 2016 7:19:34 AM
> Subject: Backport a Security Fix for CVE-2015-7833 to v4.1
>
> Hi Sasha,
>
> I conformed that these patches for CVE-2015-7833 not applied at v4.1.21.
> 588afcc1c0e45358159090d95bf7b246fb67565
> fa52bd506f274b7619955917abfde355e3d19ff
> Could you please apply this CVE-2015-7833 fix for 4.1-stable ?
>
> References:
> https://security-tracker.debian.org/tracker/CVE-2015-7833
> https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=588afcc1c0e45358159090d95bf7b246fb67565f
> https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=fa52bd506f274b7619955917abfde355e3d19ffe
>
> Regards,
> Yuki Machida
>

^ permalink raw reply	[flat|nested] 11+ messages in thread

* Re: Backport a Security Fix for CVE-2015-7833 to v4.1
  2016-04-15  8:49   ` Hans Verkuil
@ 2016-04-15  9:57     ` Vladis Dronov
  0 siblings, 0 replies; 11+ messages in thread
From: Vladis Dronov @ 2016-04-15  9:57 UTC (permalink / raw)
  To: Hans Verkuil
  Cc: Yuki Machida, sasha levin, linux-media, stable, oneukum, mchehab, ralf

Hello, Hans!

>> Having looked at it I agree that it should be reverted and I will apply it.
Thank you! I'm happy this is now somehow resolved.

Best regards,
Vladis Dronov | Red Hat, Inc. | Product Security Engineer

^ permalink raw reply	[flat|nested] 11+ messages in thread

* Re: Backport a Security Fix for CVE-2015-7833 to v4.1
  2016-04-15  9:55     ` Vladis Dronov
@ 2016-04-18  8:32       ` Yuki Machida
  2016-04-18  9:20         ` Vladis Dronov
  2016-04-18  9:01       ` Yuki Machida
  1 sibling, 1 reply; 11+ messages in thread
From: Yuki Machida @ 2016-04-18  8:32 UTC (permalink / raw)
  To: Vladis Dronov
  Cc: sasha levin, linux-media, stable, hverkuil, oneukum, mchehab, ralf

Hi Vladis,

On 2016年04月15日 18:55, Vladis Dronov wrote:
> Hello, Yuki, all,
>
> My commit fa52bd506f resolves CVE-2015-7833, as mentioned in
> https://www.spinics.net/lists/linux-media/msg96936.html
I understand that commit fa52bd506f resolved security issue of CVE-2015-7833
and commit 588afcc1 is not needed for fixing of CVE-2015-7833.

> Please, note a message from Hans down this thread, who agrees
> with my point.
I understand the opinion of Vladis and Hans.
Why "usbvision: revert commit 588afcc1" is not accepted in linux-media ?

>
> Best regards,
> Vladis Dronov | Red Hat, Inc. | Product Security Engineer
>
> ----- Original Message -----
> From: "Yuki Machida" <machida.yuki@jp.fujitsu.com>
> To: "Vladis Dronov" <vdronov@redhat.com>
> Cc: "sasha levin" <sasha.levin@oracle.com>, linux-media@vger.kernel.org, stable@vger.kernel.org, hverkuil@xs4all.nl, oneukum@suse.com, mchehab@osg.samsung.com, ralf@spenneberg.net
> Sent: Friday, April 15, 2016 10:31:17 AM
> Subject: Re: Backport a Security Fix for CVE-2015-7833 to v4.1
>
> Hi Vladis,
>
>   > I apologize for intercepting, but I believe commit 588afcc1 should
>   > not be accepted and reverted in the trees where it was.
>   >
>   > Reasons:
>   >
>   > https://patchwork.linuxtv.org/patch/32798/
>   > or
>   > https://www.spinics.net/lists/linux-media/msg96936.html
> Thank you for your reply.
>
> If it revert commit 588afcc1 from the kernel,
> It exists a Security Issue of CVE-2015-7833.
> What do you think about it?
>
> Best regards,
> Yuki Machida
>
> On 2016年04月11日 21:03, Vladis Dronov wrote:
>> Hello,
>>
>> I apologize for intercepting, but I believe commit 588afcc1 should
>> not be accepted and reverted in the trees where it was.
>>
>> Reasons:
>>
>> https://patchwork.linuxtv.org/patch/32798/
>> or
>> https://www.spinics.net/lists/linux-media/msg96936.html
>>
>>
>> Best regards,
>> Vladis Dronov | Red Hat, Inc. | Product Security Engineer
>>
>> ----- Original Message -----
>> From: "Yuki Machida" <machida.yuki@jp.fujitsu.com>
>> To: "sasha levin" <sasha.levin@oracle.com>
>> Cc: linux-media@vger.kernel.org, stable@vger.kernel.org, hverkuil@xs4all.nl, oneukum@suse.com, vdronov@redhat.com, mchehab@osg.samsung.com, ralf@spenneberg.net
>> Sent: Monday, April 11, 2016 7:19:34 AM
>> Subject: Backport a Security Fix for CVE-2015-7833 to v4.1
>>
>> Hi Sasha,
>>
>> I conformed that these patches for CVE-2015-7833 not applied at v4.1.21.
>> 588afcc1c0e45358159090d95bf7b246fb67565
>> fa52bd506f274b7619955917abfde355e3d19ff
>> Could you please apply this CVE-2015-7833 fix for 4.1-stable ?
>>
>> References:
>> https://security-tracker.debian.org/tracker/CVE-2015-7833
>> https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=588afcc1c0e45358159090d95bf7b246fb67565f
>> https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=fa52bd506f274b7619955917abfde355e3d19ffe
>>
>> Regards,
>> Yuki Machida
>>
> --
> To unsubscribe from this list: send the line "unsubscribe stable" in
> the body of a message to majordomo@vger.kernel.org
> More majordomo info at  http://vger.kernel.org/majordomo-info.html
>

Regards,
Yuki Machida

^ permalink raw reply	[flat|nested] 11+ messages in thread

* Re: Backport a Security Fix for CVE-2015-7833 to v4.1
  2016-04-15  9:55     ` Vladis Dronov
  2016-04-18  8:32       ` Yuki Machida
@ 2016-04-18  9:01       ` Yuki Machida
  2016-04-19  5:55         ` Greg KH
  1 sibling, 1 reply; 11+ messages in thread
From: Yuki Machida @ 2016-04-18  9:01 UTC (permalink / raw)
  To: sasha levin, gregkh
  Cc: Vladis Dronov, linux-media, stable, hverkuil, oneukum, mchehab, ralf

Hi Greg and Sasha,

Please do not accept patch of 588afcc to stable tree,
because above patch has some problem.
It reported by Vladis and Hans.
https://patchwork.linuxtv.org/patch/32798/
https://www.spinics.net/lists/linux-media/msg96936.html
http://article.gmane.org/gmane.linux.kernel.stable/174202/match=cve+2015+7833

Thank you for your help.

Regards,
Yuki Machida

On 2016年04月15日 18:55, Vladis Dronov wrote:
> Hello, Yuki, all,
>
> My commit fa52bd506f resolves CVE-2015-7833, as mentioned in
> https://www.spinics.net/lists/linux-media/msg96936.html
>
> Please, note a message from Hans down this thread, who agrees
> with my point.
>
> Best regards,
> Vladis Dronov | Red Hat, Inc. | Product Security Engineer
>
> ----- Original Message -----
> From: "Yuki Machida" <machida.yuki@jp.fujitsu.com>
> To: "Vladis Dronov" <vdronov@redhat.com>
> Cc: "sasha levin" <sasha.levin@oracle.com>, linux-media@vger.kernel.org, stable@vger.kernel.org, hverkuil@xs4all.nl, oneukum@suse.com, mchehab@osg.samsung.com, ralf@spenneberg.net
> Sent: Friday, April 15, 2016 10:31:17 AM
> Subject: Re: Backport a Security Fix for CVE-2015-7833 to v4.1
>
> Hi Vladis,
>
>   > I apologize for intercepting, but I believe commit 588afcc1 should
>   > not be accepted and reverted in the trees where it was.
>   >
>   > Reasons:
>   >
>   > https://patchwork.linuxtv.org/patch/32798/
>   > or
>   > https://www.spinics.net/lists/linux-media/msg96936.html
> Thank you for your reply.
>
> If it revert commit 588afcc1 from the kernel,
> It exists a Security Issue of CVE-2015-7833.
> What do you think about it?
>
> Best regards,
> Yuki Machida
>
> On 2016年04月11日 21:03, Vladis Dronov wrote:
>> Hello,
>>
>> I apologize for intercepting, but I believe commit 588afcc1 should
>> not be accepted and reverted in the trees where it was.
>>
>> Reasons:
>>
>> https://patchwork.linuxtv.org/patch/32798/
>> or
>> https://www.spinics.net/lists/linux-media/msg96936.html
>>
>>
>> Best regards,
>> Vladis Dronov | Red Hat, Inc. | Product Security Engineer
>>
>> ----- Original Message -----
>> From: "Yuki Machida" <machida.yuki@jp.fujitsu.com>
>> To: "sasha levin" <sasha.levin@oracle.com>
>> Cc: linux-media@vger.kernel.org, stable@vger.kernel.org, hverkuil@xs4all.nl, oneukum@suse.com, vdronov@redhat.com, mchehab@osg.samsung.com, ralf@spenneberg.net
>> Sent: Monday, April 11, 2016 7:19:34 AM
>> Subject: Backport a Security Fix for CVE-2015-7833 to v4.1
>>
>> Hi Sasha,
>>
>> I conformed that these patches for CVE-2015-7833 not applied at v4.1.21.
>> 588afcc1c0e45358159090d95bf7b246fb67565
>> fa52bd506f274b7619955917abfde355e3d19ff
>> Could you please apply this CVE-2015-7833 fix for 4.1-stable ?
>>
>> References:
>> https://security-tracker.debian.org/tracker/CVE-2015-7833
>> https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=588afcc1c0e45358159090d95bf7b246fb67565f
>> https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=fa52bd506f274b7619955917abfde355e3d19ffe
>>
>> Regards,
>> Yuki Machida
>>
> --
> To unsubscribe from this list: send the line "unsubscribe stable" in
> the body of a message to majordomo@vger.kernel.org
> More majordomo info at  http://vger.kernel.org/majordomo-info.html
>

^ permalink raw reply	[flat|nested] 11+ messages in thread

* Re: Backport a Security Fix for CVE-2015-7833 to v4.1
  2016-04-18  8:32       ` Yuki Machida
@ 2016-04-18  9:20         ` Vladis Dronov
  2016-04-19  8:17           ` Yuki Machida
  0 siblings, 1 reply; 11+ messages in thread
From: Vladis Dronov @ 2016-04-18  9:20 UTC (permalink / raw)
  To: Yuki Machida
  Cc: sasha levin, linux-media, stable, hverkuil, oneukum, mchehab, ralf

Hello, Yuki, all,

> Why "usbvision: revert commit 588afcc1" is not accepted in linux-media ?

As mentioned in a message from Hans down this thread, it "fell through the cracks",
unfortunately. (http://www.spinics.net/lists/linux-media/msg99495.html)

Best regards,
Vladis Dronov | Red Hat, Inc. | Product Security Engineer

----- Original Message -----
From: "Yuki Machida" <machida.yuki@jp.fujitsu.com>
To: "Vladis Dronov" <vdronov@redhat.com>
Cc: "sasha levin" <sasha.levin@oracle.com>, linux-media@vger.kernel.org, stable@vger.kernel.org, hverkuil@xs4all.nl, oneukum@suse.com, mchehab@osg.samsung.com, ralf@spenneberg.net
Sent: Monday, April 18, 2016 10:32:12 AM
Subject: Re: Backport a Security Fix for CVE-2015-7833 to v4.1

Hi Vladis,

On 2016年04月15日 18:55, Vladis Dronov wrote:
> Hello, Yuki, all,
>
> My commit fa52bd506f resolves CVE-2015-7833, as mentioned in
> https://www.spinics.net/lists/linux-media/msg96936.html
I understand that commit fa52bd506f resolved security issue of CVE-2015-7833
and commit 588afcc1 is not needed for fixing of CVE-2015-7833.

> Please, note a message from Hans down this thread, who agrees
> with my point.
I understand the opinion of Vladis and Hans.
Why "usbvision: revert commit 588afcc1" is not accepted in linux-media ?

Regards,
Yuki Machida

^ permalink raw reply	[flat|nested] 11+ messages in thread

* Re: Backport a Security Fix for CVE-2015-7833 to v4.1
  2016-04-18  9:01       ` Yuki Machida
@ 2016-04-19  5:55         ` Greg KH
  0 siblings, 0 replies; 11+ messages in thread
From: Greg KH @ 2016-04-19  5:55 UTC (permalink / raw)
  To: Yuki Machida
  Cc: sasha levin, Vladis Dronov, linux-media, stable, hverkuil,
	oneukum, mchehab, ralf

On Mon, Apr 18, 2016 at 06:01:19PM +0900, Yuki Machida wrote:
> Hi Greg and Sasha,
> 
> Please do not accept patch of 588afcc to stable tree,
> because above patch has some problem.
> It reported by Vladis and Hans.
> https://patchwork.linuxtv.org/patch/32798/
> https://www.spinics.net/lists/linux-media/msg96936.html
> http://article.gmane.org/gmane.linux.kernel.stable/174202/match=cve+2015+7833

Ok, now dropped from the 3.14-stable and 4.4-stable queues, thanks.

greg k-h

^ permalink raw reply	[flat|nested] 11+ messages in thread

* Re: Backport a Security Fix for CVE-2015-7833 to v4.1
  2016-04-18  9:20         ` Vladis Dronov
@ 2016-04-19  8:17           ` Yuki Machida
  0 siblings, 0 replies; 11+ messages in thread
From: Yuki Machida @ 2016-04-19  8:17 UTC (permalink / raw)
  To: Vladis Dronov
  Cc: sasha levin, linux-media, stable, hverkuil, oneukum, mchehab, ralf

Hi Vladis,

 >> Why "usbvision: revert commit 588afcc1" is not accepted in linux-media ?
 >
 > As mentioned in a message from Hans down this thread, it "fell through the cracks",
 > unfortunately. (http://www.spinics.net/lists/linux-media/msg99495.html)
I understand.
Thank you for you reply.

Regards,
Yuki Machida

On 2016年04月18日 18:20, Vladis Dronov wrote:
> Hello, Yuki, all,
>
>> Why "usbvision: revert commit 588afcc1" is not accepted in linux-media ?
>
> As mentioned in a message from Hans down this thread, it "fell through the cracks",
> unfortunately. (http://www.spinics.net/lists/linux-media/msg99495.html)
>
> Best regards,
> Vladis Dronov | Red Hat, Inc. | Product Security Engineer
>
> ----- Original Message -----
> From: "Yuki Machida" <machida.yuki@jp.fujitsu.com>
> To: "Vladis Dronov" <vdronov@redhat.com>
> Cc: "sasha levin" <sasha.levin@oracle.com>, linux-media@vger.kernel.org, stable@vger.kernel.org, hverkuil@xs4all.nl, oneukum@suse.com, mchehab@osg.samsung.com, ralf@spenneberg.net
> Sent: Monday, April 18, 2016 10:32:12 AM
> Subject: Re: Backport a Security Fix for CVE-2015-7833 to v4.1
>
> Hi Vladis,
>
> On 2016年04月15日 18:55, Vladis Dronov wrote:
>> Hello, Yuki, all,
>>
>> My commit fa52bd506f resolves CVE-2015-7833, as mentioned in
>> https://www.spinics.net/lists/linux-media/msg96936.html
> I understand that commit fa52bd506f resolved security issue of CVE-2015-7833
> and commit 588afcc1 is not needed for fixing of CVE-2015-7833.
>
>> Please, note a message from Hans down this thread, who agrees
>> with my point.
> I understand the opinion of Vladis and Hans.
> Why "usbvision: revert commit 588afcc1" is not accepted in linux-media ?
>
> Regards,
> Yuki Machida
>

^ permalink raw reply	[flat|nested] 11+ messages in thread

end of thread, other threads:[~2016-04-19  8:17 UTC | newest]

Thread overview: 11+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2016-04-11  5:19 Backport a Security Fix for CVE-2015-7833 to v4.1 Yuki Machida
2016-04-11 12:03 ` Vladis Dronov
2016-04-15  8:31   ` Yuki Machida
2016-04-15  9:55     ` Vladis Dronov
2016-04-18  8:32       ` Yuki Machida
2016-04-18  9:20         ` Vladis Dronov
2016-04-19  8:17           ` Yuki Machida
2016-04-18  9:01       ` Yuki Machida
2016-04-19  5:55         ` Greg KH
2016-04-15  8:49   ` Hans Verkuil
2016-04-15  9:57     ` Vladis Dronov

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).