cip-dev.lists.cip-project.org archive mirror
 help / color / mirror / Atom feed
* [cip-dev] Cip-kernel-sec Updates for Week of 2020-12-10
@ 2020-12-10  4:26 Chen-Yu Tsai (Moxa)
  0 siblings, 0 replies; only message in thread
From: Chen-Yu Tsai (Moxa) @ 2020-12-10  4:26 UTC (permalink / raw)
  To: cip-dev; +Cc: Pavel Machek, Nobuhiro Iwamatsu, masashi.kudo

[-- Attachment #1: Type: text/plain, Size: 827 bytes --]

Hi everyone,

Here is the cip-kernel-sec report for this week.

This week we have five new issues:

- CVE-2020-27786 [rawmidi UAF race condition]
  - fixed for all stable kernels
- CVE-2020-27820 [drm/nouveau UAF]
  - fix in progress; ignore for CIP
- CVE-2020-27830 [speakup crash]
  - fixed in mainline; ignore for CIP
  - backport failed for v4.14 and v5.4
- CVE-2020-28588 [collect_syscall() data leak]
  - fixed but was not tagged for stable
- CVE-2020-29534 [io_uring FD leak across execve]
  - fixed for relevant stable kernels

Regarding nouveau, it seems that the driver is enabled in hitachi_omap
defconfigs for both 4.4 and 4.19. This doesn't make sense as the configs
are for OMAP platforms which AFAIK don't have PCI for a graphics card.
We should ask if this was added by accident and remove it.


Regards
ChenYu

[-- Attachment #2: Type: text/plain, Size: 420 bytes --]


-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#5949): https://lists.cip-project.org/g/cip-dev/message/5949
Mute This Topic: https://lists.cip-project.org/mt/78847618/4520388
Group Owner: cip-dev+owner@lists.cip-project.org
Unsubscribe: https://lists.cip-project.org/g/cip-dev/leave/8129055/727948398/xyzzy [cip-dev@archiver.kernel.org]
-=-=-=-=-=-=-=-=-=-=-=-


^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2020-12-10  4:26 UTC | newest]

Thread overview: (only message) (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2020-12-10  4:26 [cip-dev] Cip-kernel-sec Updates for Week of 2020-12-10 Chen-Yu Tsai (Moxa)

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).