Re: 3.18.43-vs2.3.7.4
Romain Rivière <[email protected]> Fri, 21 Oct 2016 15:24:23 +0200
| Newsgroups | gmane.linux.vserver |
|---|---|
| Message-ID | <[email protected]> |
On 21/10/16 14:57, Herbert Poetzl wrote: > Did you check that the CVE is relevant for 3.18.x? > > If so, it should be easy to fix with a small patch. > > Not sure that we care about the ASN.1 parser though. From what I can gather, it is, having been introduced in 3.10-rc1. The faulty code is still in 3.18 and the fix found here https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=23c8a812dc3c621009e4f0e5342aa4e2ede1ceaa applies nicely to 3.18.43. Dunno why it hasn't been backported though. HTH -- Romain