From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1756480AbcASRBH (ORCPT ); Tue, 19 Jan 2016 12:01:07 -0500 Received: from mail-vk0-f45.google.com ([209.85.213.45]:36797 "EHLO mail-vk0-f45.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1754881AbcASRA6 (ORCPT ); Tue, 19 Jan 2016 12:00:58 -0500 MIME-Version: 1.0 In-Reply-To: <569E6ADC.2090306@hurleysoftware.com> References: <20160119112812.GA10818@mwanda> <569E6ADC.2090306@hurleysoftware.com> Date: Tue, 19 Jan 2016 12:00:57 -0500 X-Google-Sender-Auth: 0l5JMTMfOs5KxUFPlb6VTHmuNX0 Message-ID: Subject: Re: 2015 kernel CVEs From: Josh Boyer To: Peter Hurley Cc: Dan Carpenter , "Linux-Kernel@Vger. Kernel. Org" , kernel-hardening@lists.openwall.com, Greg KH Content-Type: text/plain; charset=UTF-8 Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Tue, Jan 19, 2016 at 11:57 AM, Peter Hurley wrote: > On 01/19/2016 03:28 AM, Dan Carpenter wrote: >> I like to look back over old CVEs to see how we could do better. Here >> is the list from 2015. I got most of this information from the Ubuntu >> CVE tracker. Thanks Ubuntu!. If it doesn't have a hash that means it >> might not be fixed yet. > > [...] > >> CVE-2015-4170 cf872776fc84: tty: hang in tty > > Makes no sense that this was assigned a CVE. > I fixed this _2 yrs before_ it was reported and the patch was CC'd stable. I'm guessing the CVE was assigned because there are distributions that ship based on kernels earlier than 3.13. Those distributors need to verify if they have the fix, etc. josh From mboxrd@z Thu Jan 1 00:00:00 1970 Reply-To: kernel-hardening@lists.openwall.com MIME-Version: 1.0 Sender: jwboyer@gmail.com In-Reply-To: <569E6ADC.2090306@hurleysoftware.com> References: <20160119112812.GA10818@mwanda> <569E6ADC.2090306@hurleysoftware.com> Date: Tue, 19 Jan 2016 12:00:57 -0500 Message-ID: From: Josh Boyer Content-Type: text/plain; charset=UTF-8 Subject: [kernel-hardening] Re: 2015 kernel CVEs To: Peter Hurley Cc: Dan Carpenter , "Linux-Kernel@Vger. Kernel. Org" , kernel-hardening@lists.openwall.com, Greg KH List-ID: On Tue, Jan 19, 2016 at 11:57 AM, Peter Hurley wrote: > On 01/19/2016 03:28 AM, Dan Carpenter wrote: >> I like to look back over old CVEs to see how we could do better. Here >> is the list from 2015. I got most of this information from the Ubuntu >> CVE tracker. Thanks Ubuntu!. If it doesn't have a hash that means it >> might not be fixed yet. > > [...] > >> CVE-2015-4170 cf872776fc84: tty: hang in tty > > Makes no sense that this was assigned a CVE. > I fixed this _2 yrs before_ it was reported and the patch was CC'd stable. I'm guessing the CVE was assigned because there are distributions that ship based on kernels earlier than 3.13. Those distributors need to verify if they have the fix, etc. josh