From: Paul Gortmaker <paul.gortmaker@windriver.com>
To: <stable@vger.kernel.org>, <linux-kernel@vger.kernel.org>
Cc: Jan Beulich <JBeulich@suse.com>, Jan Beulich <jbeulich@suse.com>,
Konrad Rzeszutek Wilk <konrad.wilk@oracle.com>,
Paul Gortmaker <paul.gortmaker@windriver.com>
Subject: [v2.6.34-stable 108/213] x86/xen: don't assume %ds is usable in xen_iret for 32-bit PVOPS.
Date: Wed, 5 Feb 2014 15:01:03 -0500 [thread overview]
Message-ID: <1391630568-49251-109-git-send-email-paul.gortmaker@windriver.com> (raw)
In-Reply-To: <1391630568-49251-1-git-send-email-paul.gortmaker@windriver.com>
From: Jan Beulich <JBeulich@suse.com>
-------------------
This is a commit scheduled for the next v2.6.34 longterm release.
http://git.kernel.org/?p=linux/kernel/git/paulg/longterm-queue-2.6.34.git
If you see a problem with using this for longterm, please comment.
-------------------
commit 13d2b4d11d69a92574a55bfd985cfb0ca77aebdc upstream.
This fixes CVE-2013-0228 / XSA-42
Drew Jones while working on CVE-2013-0190 found that that unprivileged guest user
in 32bit PV guest can use to crash the > guest with the panic like this:
-------------
general protection fault: 0000 [#1] SMP
last sysfs file: /sys/devices/vbd-51712/block/xvda/dev
Modules linked in: sunrpc ipt_REJECT nf_conntrack_ipv4 nf_defrag_ipv4
iptable_filter ip_tables ip6t_REJECT nf_conntrack_ipv6 nf_defrag_ipv6
xt_state nf_conntrack ip6table_filter ip6_tables ipv6 xen_netfront ext4
mbcache jbd2 xen_blkfront dm_mirror dm_region_hash dm_log dm_mod [last
unloaded: scsi_wait_scan]
Pid: 1250, comm: r Not tainted 2.6.32-356.el6.i686 #1
EIP: 0061:[<c0407462>] EFLAGS: 00010086 CPU: 0
EIP is at xen_iret+0x12/0x2b
EAX: eb8d0000 EBX: 00000001 ECX: 08049860 EDX: 00000010
ESI: 00000000 EDI: 003d0f00 EBP: b77f8388 ESP: eb8d1fe0
DS: 0000 ES: 007b FS: 0000 GS: 00e0 SS: 0069
Process r (pid: 1250, ti=eb8d0000 task=c2953550 task.ti=eb8d0000)
Stack:
00000000 0027f416 00000073 00000206 b77f8364 0000007b 00000000 00000000
Call Trace:
Code: c3 8b 44 24 18 81 4c 24 38 00 02 00 00 8d 64 24 30 e9 03 00 00 00
8d 76 00 f7 44 24 08 00 00 02 80 75 33 50 b8 00 e0 ff ff 21 e0 <8b> 40
10 8b 04 85 a0 f6 ab c0 8b 80 0c b0 b3 c0 f6 44 24 0d 02
EIP: [<c0407462>] xen_iret+0x12/0x2b SS:ESP 0069:eb8d1fe0
general protection fault: 0000 [#2]
---[ end trace ab0d29a492dcd330 ]---
Kernel panic - not syncing: Fatal exception
Pid: 1250, comm: r Tainted: G D ---------------
2.6.32-356.el6.i686 #1
Call Trace:
[<c08476df>] ? panic+0x6e/0x122
[<c084b63c>] ? oops_end+0xbc/0xd0
[<c084b260>] ? do_general_protection+0x0/0x210
[<c084a9b7>] ? error_code+0x73/
-------------
Petr says: "
I've analysed the bug and I think that xen_iret() cannot cope with
mangled DS, in this case zeroed out (null selector/descriptor) by either
xen_failsafe_callback() or RESTORE_REGS because the corresponding LDT
entry was invalidated by the reproducer. "
Jan took a look at the preliminary patch and came up a fix that solves
this problem:
"This code gets called after all registers other than those handled by
IRET got already restored, hence a null selector in %ds or a non-null
one that got loaded from a code or read-only data descriptor would
cause a kernel mode fault (with the potential of crashing the kernel
as a whole, if panic_on_oops is set)."
The way to fix this is to realize that the we can only relay on the
registers that IRET restores. The two that are guaranteed are the
%cs and %ss as they are always fixed GDT selectors. Also they are
inaccessible from user mode - so they cannot be altered. This is
the approach taken in this patch.
Another alternative option suggested by Jan would be to relay on
the subtle realization that using the %ebp or %esp relative references uses
the %ss segment. In which case we could switch from using %eax to %ebp and
would not need the %ss over-rides. That would also require one extra
instruction to compensate for the one place where the register is used
as scaled index. However Andrew pointed out that is too subtle and if
further work was to be done in this code-path it could escape folks attention
and lead to accidents.
Reviewed-by: Petr Matousek <pmatouse@redhat.com>
Reported-by: Petr Matousek <pmatouse@redhat.com>
Reviewed-by: Andrew Cooper <andrew.cooper3@citrix.com>
Signed-off-by: Jan Beulich <jbeulich@suse.com>
Signed-off-by: Konrad Rzeszutek Wilk <konrad.wilk@oracle.com>
Signed-off-by: Paul Gortmaker <paul.gortmaker@windriver.com>
---
arch/x86/xen/xen-asm_32.S | 14 +++++++-------
1 file changed, 7 insertions(+), 7 deletions(-)
diff --git a/arch/x86/xen/xen-asm_32.S b/arch/x86/xen/xen-asm_32.S
index b040b0e518ca..7328f71651e1 100644
--- a/arch/x86/xen/xen-asm_32.S
+++ b/arch/x86/xen/xen-asm_32.S
@@ -88,11 +88,11 @@ ENTRY(xen_iret)
*/
#ifdef CONFIG_SMP
GET_THREAD_INFO(%eax)
- movl TI_cpu(%eax), %eax
- movl __per_cpu_offset(,%eax,4), %eax
- mov xen_vcpu(%eax), %eax
+ movl %ss:TI_cpu(%eax), %eax
+ movl %ss:__per_cpu_offset(,%eax,4), %eax
+ mov %ss:xen_vcpu(%eax), %eax
#else
- movl xen_vcpu, %eax
+ movl %ss:xen_vcpu, %eax
#endif
/* check IF state we're restoring */
@@ -105,11 +105,11 @@ ENTRY(xen_iret)
* resuming the code, so we don't have to be worried about
* being preempted to another CPU.
*/
- setz XEN_vcpu_info_mask(%eax)
+ setz %ss:XEN_vcpu_info_mask(%eax)
xen_iret_start_crit:
/* check for unmasked and pending */
- cmpw $0x0001, XEN_vcpu_info_pending(%eax)
+ cmpw $0x0001, %ss:XEN_vcpu_info_pending(%eax)
/*
* If there's something pending, mask events again so we can
@@ -117,7 +117,7 @@ xen_iret_start_crit:
* touch XEN_vcpu_info_mask.
*/
jne 1f
- movb $1, XEN_vcpu_info_mask(%eax)
+ movb $1, %ss:XEN_vcpu_info_mask(%eax)
1: popl %eax
--
1.8.5.2
next prev parent reply other threads:[~2014-02-05 20:46 UTC|newest]
Thread overview: 218+ messages / expand[flat|nested] mbox.gz Atom feed top
2014-02-05 19:59 [v2.6.34-stable 000/213] v2.6.34.15 longterm review Paul Gortmaker
2014-02-05 19:59 ` [v2.6.34-stable 001/213] x86, random: make ARCH_RANDOM prompt if EMBEDDED, not EXPERT Paul Gortmaker
2014-02-05 19:59 ` [v2.6.34-stable 002/213] udf: fix udf_error build warnings Paul Gortmaker
2014-02-05 19:59 ` [v2.6.34-stable 003/213] Revert "percpu: fix chunk range calculation" Paul Gortmaker
2014-02-05 19:59 ` [v2.6.34-stable 004/213] crypto: ghash - Avoid null pointer dereference if no key is set Paul Gortmaker
2014-02-05 20:30 ` Nick Bowler
2014-02-05 20:38 ` Paul Gortmaker
2014-02-05 19:59 ` [v2.6.34-stable 005/213] inet: add RCU protection to inet->opt Paul Gortmaker
2014-02-05 19:59 ` [v2.6.34-stable 006/213] inotify: fix double free/corruption of stuct user Paul Gortmaker
2014-02-05 19:59 ` [v2.6.34-stable 007/213] KVM: unmap pages from the iommu when slots are removed Paul Gortmaker
2014-02-05 19:59 ` [v2.6.34-stable 008/213] KVM: lock slots_lock around device assignment Paul Gortmaker
2014-02-05 19:59 ` [v2.6.34-stable 009/213] bridge: Fix mglist corruption that leads to memory corruption Paul Gortmaker
2014-02-05 19:59 ` [v2.6.34-stable 010/213] block: add and use scsi_blk_cmd_ioctl Paul Gortmaker
2014-02-05 19:59 ` [v2.6.34-stable 011/213] block: fail SCSI passthrough ioctls on partition devices Paul Gortmaker
2014-02-05 19:59 ` [v2.6.34-stable 012/213] dm: do not forward ioctls from logical volumes to the underlying device Paul Gortmaker
2014-02-05 19:59 ` [v2.6.34-stable 013/213] libceph: Fix NULL pointer dereference in auth client code Paul Gortmaker
2014-02-05 19:59 ` [v2.6.34-stable 014/213] ipv6: call udp_push_pending_frames when uncorking a socket with AF_INET pending data Paul Gortmaker
2014-02-05 19:59 ` [v2.6.34-stable 015/213] jbd/jbd2: validate sb->s_first in journal_get_superblock() Paul Gortmaker
2014-02-05 19:59 ` [v2.6.34-stable 016/213] crypto: ansi_cprng - Fix off by one error in non-block size request Paul Gortmaker
2014-02-05 19:59 ` [v2.6.34-stable 017/213] HID: validate HID report id size Paul Gortmaker
2014-02-05 19:59 ` [v2.6.34-stable 018/213] HID: pantherlord: validate output report details Paul Gortmaker
2014-02-05 19:59 ` [v2.6.34-stable 019/213] HID: provide a helper for validating hid reports Paul Gortmaker
2014-02-05 19:59 ` [v2.6.34-stable 020/213] HID: zeroplus: validate output report details Paul Gortmaker
2014-02-05 19:59 ` [v2.6.34-stable 021/213] HID: LG: validate HID " Paul Gortmaker
2014-02-05 19:59 ` [v2.6.34-stable 022/213] rose: fix info leak via msg_name in rose_recvmsg() Paul Gortmaker
2014-02-05 19:59 ` [v2.6.34-stable 023/213] rds: set correct msg_namelen Paul Gortmaker
2014-02-05 19:59 ` [v2.6.34-stable 024/213] llc: fix info leak via getsockname() Paul Gortmaker
2014-02-05 19:59 ` [v2.6.34-stable 025/213] llc: Fix missing msg_namelen update in llc_ui_recvmsg() Paul Gortmaker
2014-02-05 19:59 ` [v2.6.34-stable 026/213] iucv: Fix missing msg_namelen update in iucv_sock_recvmsg() Paul Gortmaker
2014-02-05 19:59 ` [v2.6.34-stable 027/213] isdnloop: fix and simplify isdnloop_init() Paul Gortmaker
2014-02-05 19:59 ` [v2.6.34-stable 028/213] ax25: fix info leak via msg_name in ax25_recvmsg() Paul Gortmaker
2014-02-05 19:59 ` [v2.6.34-stable 029/213] atm: fix info leak in getsockopt(SO_ATMPVC) Paul Gortmaker
2014-02-05 19:59 ` [v2.6.34-stable 030/213] atm: fix info leak via getsockname() Paul Gortmaker
2014-02-05 19:59 ` [v2.6.34-stable 031/213] atm: update msg_namelen in vcc_recvmsg() Paul Gortmaker
2014-02-05 19:59 ` [v2.6.34-stable 032/213] ipvs: fix info leak in getsockopt(IP_VS_SO_GET_TIMEOUT) Paul Gortmaker
2014-02-05 20:36 ` Julian Anastasov
2014-02-05 20:58 ` Julian Anastasov
2014-02-05 19:59 ` [v2.6.34-stable 033/213] netfilter: nf_ct_ipv4: packets with wrong ihl are invalid Paul Gortmaker
2014-02-05 19:59 ` [v2.6.34-stable 034/213] net: sctp: sctp_auth_key_put: use kzfree instead of kfree Paul Gortmaker
2014-02-05 19:59 ` [v2.6.34-stable 035/213] net: sctp: sctp_endpoint_free: zero out secret key data Paul Gortmaker
2014-02-05 19:59 ` [v2.6.34-stable 036/213] net: sctp: sctp_setsockopt_auth_key: use kzfree instead of kfree Paul Gortmaker
2014-02-05 19:59 ` [v2.6.34-stable 037/213] sctp: fix memory leak in sctp_datamsg_from_user() when copy from user space fails Paul Gortmaker
2014-02-05 19:59 ` [v2.6.34-stable 038/213] unix: fix a race condition in unix_release() Paul Gortmaker
2014-02-05 19:59 ` [v2.6.34-stable 039/213] tcp: allow splice() to build full TSO packets Paul Gortmaker
2014-02-05 19:59 ` [v2.6.34-stable 040/213] tcp: tcp_sendpages() should call tcp_push() once Paul Gortmaker
2014-02-05 19:59 ` [v2.6.34-stable 041/213] tcp: fix MSG_SENDPAGE_NOTLAST logic Paul Gortmaker
2014-02-05 19:59 ` [v2.6.34-stable 042/213] tcp: preserve ACK clocking in TSO Paul Gortmaker
2014-02-05 19:59 ` [v2.6.34-stable 043/213] net: fix info leak in compat dev_ifconf() Paul Gortmaker
2014-02-05 19:59 ` [v2.6.34-stable 044/213] net: guard tcp_set_keepalive() to tcp sockets Paul Gortmaker
2014-02-05 20:00 ` [v2.6.34-stable 045/213] net: fix divide by zero in tcp algorithm illinois Paul Gortmaker
2014-02-05 20:00 ` [v2.6.34-stable 046/213] net: prevent setting ttl=0 via IP_TTL Paul Gortmaker
2014-02-05 20:00 ` [v2.6.34-stable 047/213] net: sched: integer overflow fix Paul Gortmaker
2014-02-05 20:00 ` [v2.6.34-stable 048/213] net_sched: gact: Fix potential panic in tcf_gact() Paul Gortmaker
2014-02-05 20:00 ` [v2.6.34-stable 049/213] bridge: set priority of STP packets Paul Gortmaker
2014-02-05 20:00 ` [v2.6.34-stable 050/213] af_packet: remove BUG statement in tpacket_destruct_skb Paul Gortmaker
2014-02-05 20:00 ` [v2.6.34-stable 051/213] netem: fix possible skb leak Paul Gortmaker
2014-02-05 20:00 ` [v2.6.34-stable 052/213] net_sched: gred: Fix oops in gred_dump() in WRED mode Paul Gortmaker
2014-02-05 20:00 ` [v2.6.34-stable 053/213] net: fix a race in sock_queue_err_skb() Paul Gortmaker
2014-02-05 20:00 ` [v2.6.34-stable 054/213] netlink: wake up netlink listeners sooner (v2) Paul Gortmaker
2014-02-05 20:00 ` [v2.6.34-stable 055/213] netlink: fix races after skb queueing Paul Gortmaker
2014-02-05 20:00 ` [v2.6.34-stable 056/213] softirq: reduce latencies Paul Gortmaker
2014-02-05 20:00 ` [v2.6.34-stable 057/213] net: reduce net_rx_action() latency to 2 HZ Paul Gortmaker
2014-02-05 20:00 ` [v2.6.34-stable 058/213] net/core: Fix potential memory leak in dev_set_alias() Paul Gortmaker
2014-02-05 20:00 ` [v2.6.34-stable 059/213] net/tun: fix ioctl() based info leaks Paul Gortmaker
2014-02-05 20:00 ` [v2.6.34-stable 060/213] tun: Fix formatting Paul Gortmaker
2014-02-05 20:00 ` [v2.6.34-stable 061/213] tcp: perform DMA to userspace only if there is a task waiting for it Paul Gortmaker
2014-02-05 20:00 ` [v2.6.34-stable 062/213] tcp: drop SYN+FIN messages Paul Gortmaker
2014-02-05 20:00 ` [v2.6.34-stable 063/213] tcp: do_tcp_sendpages() must try to push data out on oom conditions Paul Gortmaker
2014-02-05 20:00 ` [v2.6.34-stable 064/213] drop_monitor: fix sleeping in invalid context warning Paul Gortmaker
2014-02-05 20:00 ` [v2.6.34-stable 065/213] drop_monitor: Make updating data->skb smp safe Paul Gortmaker
2014-02-05 20:00 ` [v2.6.34-stable 066/213] drop_monitor: prevent init path from scheduling on the wrong cpu Paul Gortmaker
2014-02-05 20:00 ` [v2.6.34-stable 067/213] drop_monitor: dont sleep in atomic context Paul Gortmaker
2014-02-05 20:00 ` [v2.6.34-stable 068/213] xfrm_user: fix info leak in copy_to_user_state() Paul Gortmaker
2014-02-05 20:00 ` [v2.6.34-stable 069/213] xfrm_user: fix info leak in copy_to_user_policy() Paul Gortmaker
2014-02-05 20:00 ` [v2.6.34-stable 070/213] xfrm_user: fix info leak in copy_to_user_tmpl() Paul Gortmaker
2014-02-05 20:00 ` [v2.6.34-stable 071/213] xfrm_user: return error pointer instead of NULL Paul Gortmaker
2014-02-05 20:00 ` [v2.6.34-stable 072/213] xfrm_user: return error pointer instead of NULL #2 Paul Gortmaker
2014-02-05 20:00 ` [v2.6.34-stable 073/213] b43legacy: Fix crash on unload when firmware not available Paul Gortmaker
2014-02-05 20:00 ` [v2.6.34-stable 074/213] tg3: Avoid null pointer dereference in tg3_interrupt in netconsole mode Paul Gortmaker
2014-02-05 20:00 ` [v2.6.34-stable 075/213] nfsd4: fix oops on unusual readlike compound Paul Gortmaker
2014-02-05 20:00 ` [v2.6.34-stable 076/213] NFSv3: Ensure that do_proc_get_root() reports errors correctly Paul Gortmaker
2014-02-05 20:00 ` [v2.6.34-stable 077/213] NFSv4: Revalidate uid/gid after open Paul Gortmaker
2014-02-05 20:00 ` [v2.6.34-stable 078/213] kernel panic when mount NFSv4 Paul Gortmaker
2014-02-05 20:00 ` [v2.6.34-stable 079/213] hfsplus: fix potential overflow in hfsplus_file_truncate() Paul Gortmaker
2014-02-05 20:00 ` [v2.6.34-stable 080/213] clockevents: Don't allow dummy broadcast timers Paul Gortmaker
2014-02-05 20:00 ` [v2.6.34-stable 081/213] posix-cpu-timers: Fix nanosleep task_struct leak Paul Gortmaker
2014-02-05 20:00 ` [v2.6.34-stable 082/213] timer: Don't reinitialize the cpu base lock during CPU_UP_PREPARE Paul Gortmaker
2014-02-05 20:00 ` [v2.6.34-stable 083/213] tick: Cleanup NOHZ per cpu data on cpu down Paul Gortmaker
2014-02-05 20:00 ` [v2.6.34-stable 084/213] gen_init_cpio: avoid stack overflow when expanding Paul Gortmaker
2014-02-05 20:00 ` [v2.6.34-stable 085/213] exec: do not leave bprm->interp on stack Paul Gortmaker
2014-02-05 20:00 ` [v2.6.34-stable 086/213] exec: use -ELOOP for max recursion depth Paul Gortmaker
2014-02-05 20:00 ` [v2.6.34-stable 087/213] ptrace: ptrace_resume() shouldn't wake up !TASK_TRACED thread Paul Gortmaker
2014-02-05 20:00 ` [v2.6.34-stable 088/213] kernel/signal.c: stop info leak via the tkill and the tgkill syscalls Paul Gortmaker
2014-02-05 20:00 ` [v2.6.34-stable 089/213] wake_up_process() should be never used to wakeup a TASK_STOPPED/TRACED task Paul Gortmaker
2014-02-05 20:00 ` [v2.6.34-stable 090/213] coredump: prevent double-free on an error path in core dumper Paul Gortmaker
2014-02-05 20:00 ` [v2.6.34-stable 091/213] kernel/sys.c: call disable_nonboot_cpus() in kernel_restart() Paul Gortmaker
2014-02-05 20:00 ` [v2.6.34-stable 092/213] kernel/resource.c: fix stack overflow in __reserve_region_with_split() Paul Gortmaker
2014-02-05 20:00 ` [v2.6.34-stable 093/213] Driver core: treat unregistered bus_types as having no devices Paul Gortmaker
2014-02-05 20:00 ` [v2.6.34-stable 094/213] cgroup: remove incorrect dget/dput() pair in cgroup_create_dir() Paul Gortmaker
2014-02-05 20:00 ` [v2.6.34-stable 095/213] Fix a dead loop in async_synchronize_full() Paul Gortmaker
2014-02-05 20:00 ` [v2.6.34-stable 096/213] Prevent interface errors with Seagate FreeAgent GoFlex Paul Gortmaker
2014-02-05 20:00 ` [v2.6.34-stable 097/213] tracing: Don't call page_to_pfn() if page is NULL Paul Gortmaker
2014-02-05 20:00 ` [v2.6.34-stable 098/213] tracing: Fix double free when function profile init failed Paul Gortmaker
2014-02-05 20:00 ` [v2.6.34-stable 099/213] hugetlb: fix resv_map leak in error path Paul Gortmaker
2014-02-05 20:00 ` [v2.6.34-stable 100/213] mm: fix vma_resv_map() NULL pointer Paul Gortmaker
2014-02-05 20:00 ` [v2.6.34-stable 101/213] mm: Fix PageHead when !CONFIG_PAGEFLAGS_EXTENDED Paul Gortmaker
2014-02-05 20:00 ` [v2.6.34-stable 102/213] mm: bugfix: set current->reclaim_state to NULL while returning from kswapd() Paul Gortmaker
2014-02-05 20:00 ` [v2.6.34-stable 103/213] mm: fix invalidate_complete_page2() lock ordering Paul Gortmaker
2014-02-05 20:00 ` [v2.6.34-stable 104/213] mm: mmu_notifier: fix freed page still mapped in secondary MMU Paul Gortmaker
2014-02-05 20:01 ` [v2.6.34-stable 105/213] mm: Hold a file reference in madvise_remove Paul Gortmaker
2014-02-05 20:01 ` [v2.6.34-stable 106/213] mempolicy: fix a race in shared_policy_replace() Paul Gortmaker
2014-02-05 20:01 ` [v2.6.34-stable 107/213] ALSA: seq: Fix missing error handling in snd_seq_timer_open() Paul Gortmaker
2014-02-05 20:01 ` Paul Gortmaker [this message]
2014-02-05 20:01 ` [v2.6.34-stable 109/213] x86/msr: Add capabilities check Paul Gortmaker
2014-02-05 20:01 ` [v2.6.34-stable 110/213] x86, tls: Off by one limit check Paul Gortmaker
2014-02-05 20:01 ` [v2.6.34-stable 111/213] x86/mm: Check if PUD is large when validating a kernel address Paul Gortmaker
2014-02-05 20:01 ` [v2.6.34-stable 112/213] x86, mm, paravirt: Fix vmalloc_fault oops during lazy MMU updates Paul Gortmaker
2014-02-05 20:01 ` [v2.6.34-stable 113/213] xen/bootup: allow read_tscp call for Xen PV guests Paul Gortmaker
2014-02-05 20:01 ` [v2.6.34-stable 114/213] xen/bootup: allow {read|write}_cr8 pvops call Paul Gortmaker
2014-02-05 20:01 ` [v2.6.34-stable 115/213] KVM: x86: fix for buffer overflow in handling of MSR_KVM_SYSTEM_TIME (CVE-2013-1796) Paul Gortmaker
2014-02-05 20:01 ` [v2.6.34-stable 116/213] KVM: Fix bounds checking in ioapic indirect register reads (CVE-2013-1798) Paul Gortmaker
2014-02-05 20:01 ` [v2.6.34-stable 117/213] MCE: Fix vm86 handling for 32bit mce handler Paul Gortmaker
2014-02-05 20:01 ` [v2.6.34-stable 118/213] ACPI / cpuidle: Fix NULL pointer issues when cpuidle is disabled Paul Gortmaker
2014-02-05 20:01 ` [v2.6.34-stable 119/213] serial: 8250, increase PASS_LIMIT Paul Gortmaker
2014-02-05 20:01 ` [v2.6.34-stable 120/213] drivers/char/ipmi: memcpy, need additional 2 bytes to avoid memory overflow Paul Gortmaker
2014-02-05 20:01 ` [v2.6.34-stable 121/213] w1: fix oops when w1_search is called from netlink connector Paul Gortmaker
2014-02-05 20:01 ` [v2.6.34-stable 122/213] fix Null pointer dereference on disk error Paul Gortmaker
2014-02-05 20:01 ` [v2.6.34-stable 123/213] fix crash in scsi_dispatch_cmd() Paul Gortmaker
2014-02-05 20:01 ` [v2.6.34-stable 124/213] bnx2i: Fixed NULL ptr deference for 1G bnx2 Linux iSCSI offload Paul Gortmaker
2014-02-05 20:01 ` [v2.6.34-stable 125/213] keys: fix race with concurrent install_user_keyrings() Paul Gortmaker
2014-02-05 20:01 ` [v2.6.34-stable 126/213] crypto: cryptd - disable softirqs in cryptd_queue_worker to prevent data corruption Paul Gortmaker
2014-02-05 20:01 ` [v2.6.34-stable 127/213] IPoIB: Fix use-after-free of multicast object Paul Gortmaker
2014-02-05 20:01 ` [v2.6.34-stable 128/213] Bluetooth: Fix incorrect strncpy() in hidp_setup_hid() Paul Gortmaker
2014-02-05 20:01 ` [v2.6.34-stable 129/213] Bluetooth: HCI - Fix info leak in getsockopt(HCI_FILTER) Paul Gortmaker
2014-02-05 20:01 ` [v2.6.34-stable 130/213] Bluetooth: RFCOMM - Fix info leak via getsockname() Paul Gortmaker
2014-02-05 20:01 ` [v2.6.34-stable 131/213] Bluetooth: RFCOMM - Fix missing msg_namelen update in rfcomm_sock_recvmsg() Paul Gortmaker
2014-02-05 20:01 ` [v2.6.34-stable 132/213] Bluetooth: L2CAP - Fix info leak via getsockname() Paul Gortmaker
2014-02-05 20:01 ` [v2.6.34-stable 133/213] Bluetooth: fix possible info leak in bt_sock_recvmsg() Paul Gortmaker
2014-02-05 20:01 ` [v2.6.34-stable 134/213] Bluetooth: add NULL pointer check in HCI Paul Gortmaker
2014-02-05 20:01 ` [v2.6.34-stable 135/213] Bluetooth: hci_ldisc: fix NULL-pointer dereference on tty_close Paul Gortmaker
2014-02-05 20:01 ` [v2.6.34-stable 136/213] xhci: Make handover code more robust Paul Gortmaker
2014-02-05 20:01 ` [v2.6.34-stable 137/213] xhci: Increase reset timeout for Renesas 720201 host Paul Gortmaker
2014-02-05 20:01 ` [v2.6.34-stable 138/213] xhci: Reset reserved command ring TRBs on cleanup Paul Gortmaker
2014-02-05 20:01 ` [v2.6.34-stable 139/213] xHCI: Correct the #define XHCI_LEGACY_DISABLE_SMI Paul Gortmaker
2014-02-05 20:01 ` [v2.6.34-stable 140/213] xhci: Don't write zeroed pointers to xHC registers Paul Gortmaker
2014-02-05 20:01 ` [v2.6.34-stable 141/213] USB: EHCI: go back to using the system clock for QH unlinks Paul Gortmaker
2014-02-05 20:01 ` [v2.6.34-stable 142/213] USB: whiteheat: fix memory leak in error path Paul Gortmaker
2014-02-05 20:01 ` [v2.6.34-stable 143/213] USB: serial: Fix memory leak in sierra_release() Paul Gortmaker
2014-02-05 20:01 ` [v2.6.34-stable 144/213] USB: mos7840: fix urb leak at release Paul Gortmaker
2014-02-05 20:01 ` [v2.6.34-stable 145/213] USB: mos7840: fix port-device leak in error path Paul Gortmaker
2014-02-05 20:01 ` [v2.6.34-stable 146/213] USB: garmin_gps: fix memory leak on disconnect Paul Gortmaker
2014-02-05 20:01 ` [v2.6.34-stable 147/213] USB: io_ti: Fix NULL dereference in chase_port() Paul Gortmaker
2014-02-05 20:01 ` [v2.6.34-stable 148/213] USB: cdc-wdm: fix buffer overflow Paul Gortmaker
2014-02-05 20:01 ` [v2.6.34-stable 149/213] USB: serial: ftdi_sio: Handle the old_termios == 0 case e.g. uart_resume_port() Paul Gortmaker
2014-02-05 20:01 ` [v2.6.34-stable 150/213] USB: CDC ACM: Fix NULL pointer dereference Paul Gortmaker
2014-02-05 20:01 ` [v2.6.34-stable 151/213] usb: serial: mos7840: Fixup mos7840_chars_in_buffer() Paul Gortmaker
2014-02-05 20:01 ` [v2.6.34-stable 152/213] USB: echi-dbgp: increase the controller wait time to come out of halt Paul Gortmaker
2014-02-05 20:01 ` [v2.6.34-stable 153/213] USB: kaweth.c: use GFP_ATOMIC under spin_lock Paul Gortmaker
2014-02-05 20:01 ` [v2.6.34-stable 154/213] USB: cdc-wdm: fix lockup on error in wdm_read Paul Gortmaker
2014-02-05 20:01 ` [v2.6.34-stable 155/213] USB: serial: fix race between probe and open Paul Gortmaker
2014-02-05 20:01 ` [v2.6.34-stable 156/213] usbdevfs: Correct amount of data copied to user in processcompl_compat Paul Gortmaker
2014-02-05 20:01 ` [v2.6.34-stable 157/213] epoll: prevent missed events on EPOLL_CTL_MOD Paul Gortmaker
2014-02-05 20:01 ` [v2.6.34-stable 158/213] fs/compat_ioctl.c: VIDEO_SET_SPU_PALETTE missing error check Paul Gortmaker
2014-02-05 20:01 ` [v2.6.34-stable 159/213] fs/fscache/stats.c: fix memory leak Paul Gortmaker
2014-02-05 20:01 ` [v2.6.34-stable 160/213] sysfs: sysfs_pathname/sysfs_add_one: Use strlcat() instead of strcat() Paul Gortmaker
2014-02-05 20:01 ` [v2.6.34-stable 161/213] tmpfs: fix use-after-free of mempolicy object Paul Gortmaker
2014-02-05 20:01 ` [v2.6.34-stable 162/213] fs/cifs/cifs_dfs_ref.c: fix potential memory leakage Paul Gortmaker
2014-02-05 20:01 ` [v2.6.34-stable 163/213] isofs: avoid info leak on export Paul Gortmaker
2014-02-05 20:01 ` [v2.6.34-stable 164/213] jbd: Fix assertion failure in commit code due to lacking transaction credits Paul Gortmaker
2014-02-05 20:02 ` [v2.6.34-stable 165/213] jbd: Fix lock ordering bug in journal_unmap_buffer() Paul Gortmaker
2014-02-05 20:02 ` [v2.6.34-stable 166/213] jbd2: clear BH_Delay & BH_Unwritten in journal_unmap_buffer Paul Gortmaker
2014-02-05 20:02 ` [v2.6.34-stable 167/213] ecryptfs: call vfs_setxattr() in ecryptfs_setxattr() Paul Gortmaker
2014-02-05 20:02 ` [v2.6.34-stable 168/213] eCryptfs: Copy up lower inode attrs after setting lower xattr Paul Gortmaker
2014-02-05 20:02 ` [v2.6.34-stable 169/213] ext3: Fix fdatasync() for files with only i_size changes Paul Gortmaker
2014-02-05 20:02 ` [v2.6.34-stable 170/213] ext3: Fix error handling on inode bitmap corruption Paul Gortmaker
2014-02-05 20:02 ` [v2.6.34-stable 171/213] ext4: don't let i_reserved_meta_blocks go negative Paul Gortmaker
2014-02-05 20:02 ` [v2.6.34-stable 172/213] ext4: Fix fs corruption when make_indexed_dir() fails Paul Gortmaker
2014-02-05 20:02 ` [v2.6.34-stable 173/213] ext4: don't dereference null pointer " Paul Gortmaker
2014-02-05 20:02 ` [v2.6.34-stable 174/213] ext4: fix memory leak in ext4_xattr_set_acl()'s error path Paul Gortmaker
2014-02-05 20:02 ` [v2.6.34-stable 175/213] ext4: online defrag is not supported for journaled files Paul Gortmaker
2014-02-05 20:02 ` [v2.6.34-stable 176/213] ext4: always set i_op in ext4_mknod() Paul Gortmaker
2014-02-05 20:02 ` [v2.6.34-stable 177/213] ext4: fix fdatasync() for files with only i_size changes Paul Gortmaker
2014-02-05 20:02 ` [v2.6.34-stable 178/213] ext4: lock i_mutex when truncating orphan inodes Paul Gortmaker
2014-02-05 20:02 ` [v2.6.34-stable 179/213] ext4: fix race in ext4_mb_add_n_trim() Paul Gortmaker
2014-02-05 20:02 ` [v2.6.34-stable 180/213] ext4: limit group search loop for non-extent files Paul Gortmaker
2014-02-05 20:02 ` [v2.6.34-stable 181/213] ext4: make orphan functions be no-op in no-journal mode Paul Gortmaker
2014-02-05 20:02 ` [v2.6.34-stable 182/213] ext4: avoid hang when mounting non-journal filesystems with orphan list Paul Gortmaker
2014-02-05 20:02 ` [v2.6.34-stable 183/213] ext4: fix error handling on inode bitmap corruption Paul Gortmaker
2014-02-05 20:02 ` [v2.6.34-stable 184/213] btrfs: use rcu_barrier() to wait for bdev puts at unmount Paul Gortmaker
2014-02-05 20:02 ` [v2.6.34-stable 185/213] Btrfs: call the ordered free operation without any locks held Paul Gortmaker
2014-02-05 20:02 ` [v2.6.34-stable 186/213] udf: fix memory leak while allocating blocks during write Paul Gortmaker
2014-02-05 20:02 ` [v2.6.34-stable 187/213] udf: avoid info leak on export Paul Gortmaker
2014-02-05 20:02 ` [v2.6.34-stable 188/213] udf: Fix bitmap overflow on large filesystems with small block size Paul Gortmaker
2014-02-05 20:02 ` [v2.6.34-stable 189/213] udf: Fix data corruption for files in ICB Paul Gortmaker
2014-02-05 20:02 ` [v2.6.34-stable 190/213] udf: fix retun value on error path in udf_load_logicalvol Paul Gortmaker
2014-02-05 20:02 ` [v2.6.34-stable 191/213] Fix install_process_keyring error handling Paul Gortmaker
2014-02-05 20:02 ` [v2.6.34-stable 192/213] mtd: cafe_nand: fix an & vs | mistake Paul Gortmaker
2014-02-05 20:02 ` [v2.6.34-stable 193/213] dccp: check ccid before dereferencing Paul Gortmaker
2014-02-05 20:02 ` [v2.6.34-stable 194/213] Remove user-triggerable BUG from mpol_to_str Paul Gortmaker
2014-02-05 20:02 ` [v2.6.34-stable 195/213] svcrpc: sends on closed socket should stop immediately Paul Gortmaker
2014-02-05 20:02 ` [v2.6.34-stable 196/213] svcrpc: fix svc_xprt_enqueue/svc_recv busy-looping Paul Gortmaker
2014-02-05 20:02 ` [v2.6.34-stable 197/213] vfs: missed source of ->f_pos races Paul Gortmaker
2014-02-05 20:02 ` [v2.6.34-stable 198/213] fuse: verify all ioctl retry iov elements Paul Gortmaker
2014-02-05 20:02 ` [v2.6.34-stable 199/213] pcdp: use early_ioremap/early_iounmap to access pcdp table Paul Gortmaker
2014-02-05 20:02 ` [v2.6.34-stable 200/213] futex: Forbid uaddr == uaddr2 in futex_wait_requeue_pi() Paul Gortmaker
2014-02-05 20:02 ` [v2.6.34-stable 201/213] futex: Fix bug in WARN_ON for NULL q.pi_state Paul Gortmaker
2014-02-05 20:02 ` [v2.6.34-stable 202/213] futex: Test for pi_mutex on fault in futex_wait_requeue_pi() Paul Gortmaker
2014-02-05 20:02 ` [v2.6.34-stable 203/213] cipso: don't follow a NULL pointer when setsockopt() is called Paul Gortmaker
2014-02-05 20:02 ` [v2.6.34-stable 204/213] Avoid dangling pointer in scsi_requeue_command() Paul Gortmaker
2014-02-05 20:02 ` [v2.6.34-stable 205/213] libsas: continue revalidation Paul Gortmaker
2014-02-05 20:02 ` [v2.6.34-stable 206/213] SCSI: libsas: fix sas_discover_devices return code handling Paul Gortmaker
2014-02-05 20:02 ` [v2.6.34-stable 207/213] fix eh wakeup (scsi_schedule_eh vs scsi_restart_operations) Paul Gortmaker
2014-02-05 20:02 ` [v2.6.34-stable 208/213] eCryptfs: Properly check for O_RDONLY flag before doing privileged open Paul Gortmaker
2014-02-05 20:02 ` [v2.6.34-stable 209/213] fuse: fix stat call on 32 bit platforms Paul Gortmaker
2014-02-05 20:02 ` [v2.6.34-stable 210/213] phonet: Check input from user before allocating Paul Gortmaker
2014-02-05 20:02 ` [v2.6.34-stable 211/213] PCI: Add quirk for still enabled interrupts on Intel Sandy Bridge GPUs Paul Gortmaker
2014-02-05 20:02 ` [v2.6.34-stable 212/213] crypto: sha512 - Fix byte counter overflow in SHA-512 Paul Gortmaker
2014-02-05 20:02 ` [v2.6.34-stable 213/213] video:uvesafb: Fix oops that uvesafb try to execute NX-protected page Paul Gortmaker
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1391630568-49251-109-git-send-email-paul.gortmaker@windriver.com \
--to=paul.gortmaker@windriver.com \
--cc=JBeulich@suse.com \
--cc=konrad.wilk@oracle.com \
--cc=linux-kernel@vger.kernel.org \
--cc=stable@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®