Re: [PATCH] tracing: Use strlcpy() instead of strcpy() in __trace_find_cmdline()

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Le 2018-12-16 20:27, Steven Rostedt a écrit :
On Sun, 16 Dec 2018 09:52:33 +0100
Greg KH <gregkh@xxxxxxxxxxxxxxxxxxx> wrote:

On Sat, Dec 15, 2018 at 06:25:37PM +0100, Loic wrote:
> Hello,
>
> Please picked up this patch for linux 4.4 and 4.9.
> This fixes CVE-2017-0605 (Rejected?). Tested in Debian ;)

It was rejected as a CVE for a good reason, and that reason is also why
I refused to add it to the stable kernel releases.  In short, this is
not an issue or bug at all, there is nothing wrong with the existing
code.


I'm starting to regret that I ever accepted the original patch :-(

-- Steve

Okay, I hadn't looked at the previous conversations because this change is in the upstream and in debian...

--
Best regards,

Loic



[Index of Archives]     [Linux Kernel]     [Kernel Development Newbies]     [Linux USB Devel]     [Video for Linux]     [Linux Audio Users]     [Yosemite Hiking]     [Linux Kernel]     [Linux SCSI]

  Powered by Linux