All of lore.kernel.org
 help / color / mirror / Atom feed
* Re: ACPICA: acpi: acpica: fix acpi operand cache leak in nseval.c
@ 2018-05-09 21:30 Mark Salyzyn
  2018-05-10  6:55 ` Greg KH
  0 siblings, 1 reply; 6+ messages in thread
From: Mark Salyzyn @ 2018-05-09 21:30 UTC (permalink / raw)
  To: stable; +Cc: Seunghun Han, Erik Schmauss, Rafael J. Wysocki, kernel-team

ToT commit 97f3c0a4b0579b646b6b10ae5a3d59f0441cc12c

(ACPICA: acpi: acpica: fix acpi operand cache leak in nseval.c)

was assigned CVE-2017-13695 
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-13695
and has been public since August 25 2017

Please apply to 3.18, 4.4 and 4.9 stable kernels for the reasons 
outlined in the body of the patch:

"This cache leak causes a security threat because an old kernel (<= 4.9) 
shows memory locations of kernel functions in stack dump. Some malicious 
users could use this information to neutralize kernel ASLR."

Bonus Points: Since the patch is ToT upstream, relieving the bug that 
results in the memory leak, even despite the non-CVE security status for 
<=4.12 kernels, it may be advised to also include this patch in 4.14.y 
stable as well.

Sincerely -- Mark Salyzyn

^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2018-05-15 20:42 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2018-05-09 21:30 ACPICA: acpi: acpica: fix acpi operand cache leak in nseval.c Mark Salyzyn
2018-05-10  6:55 ` Greg KH
2018-05-10 18:45   ` Schmauss, Erik
2018-05-11  5:23     ` Greg KH
2018-05-15 17:36       ` Schmauss, Erik
2018-05-15 20:42         ` Mark Salyzyn

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.