* Re: CVE-2024-26831: net/handshake: Fix handshake_req_destroy_test1
[not found] <2024041704-CVE-2024-26831-2e6e@gregkh>
@ 2024-06-11 8:21 ` Vegard Nossum
2024-06-13 13:59 ` Greg Kroah-Hartman
0 siblings, 1 reply; 2+ messages in thread
From: Vegard Nossum @ 2024-06-11 8:21 UTC (permalink / raw)
To: cve, linux-kernel, linux-cve-announce
Cc: Greg Kroah-Hartman, Guenter Roeck, Chuck Lever, Hannes Reinecke,
Jakub Kicinski, Harshit Mogalapalli
On 17/04/2024 11:44, Greg Kroah-Hartman wrote:
> Description
> ===========
>
> In the Linux kernel, the following vulnerability has been resolved:
>
> net/handshake: Fix handshake_req_destroy_test1
>
> Recently, handshake_req_destroy_test1 started failing:
[...]
> Affected files
> ==============
>
> The file(s) affected by this issue are:
> net/handshake/handshake-test.c
Hi,
This patch
(https://git.kernel.org/torvalds/c/4e1d71cabb19ec2586827adfc60d68689c68c194)
fixes a kunit test; we therefore believe this is not a vulnerability.
Thanks,
Vegard
^ permalink raw reply [flat|nested] 2+ messages in thread
* Re: CVE-2024-26831: net/handshake: Fix handshake_req_destroy_test1
2024-06-11 8:21 ` CVE-2024-26831: net/handshake: Fix handshake_req_destroy_test1 Vegard Nossum
@ 2024-06-13 13:59 ` Greg Kroah-Hartman
0 siblings, 0 replies; 2+ messages in thread
From: Greg Kroah-Hartman @ 2024-06-13 13:59 UTC (permalink / raw)
To: Vegard Nossum
Cc: cve, linux-kernel, linux-cve-announce, Guenter Roeck,
Chuck Lever, Hannes Reinecke, Jakub Kicinski,
Harshit Mogalapalli
On Tue, Jun 11, 2024 at 10:21:47AM +0200, Vegard Nossum wrote:
>
> On 17/04/2024 11:44, Greg Kroah-Hartman wrote:
> > Description
> > ===========
> >
> > In the Linux kernel, the following vulnerability has been resolved:
> >
> > net/handshake: Fix handshake_req_destroy_test1
> >
> > Recently, handshake_req_destroy_test1 started failing:
>
> [...]
>
> > Affected files
> > ==============
> >
> > The file(s) affected by this issue are:
> > net/handshake/handshake-test.c
>
> Hi,
>
> This patch
> (https://git.kernel.org/torvalds/c/4e1d71cabb19ec2586827adfc60d68689c68c194)
> fixes a kunit test; we therefore believe this is not a vulnerability.
Many systems build kunit tests into the kernels they ship to customers
(hint, a few hundred million phones have them enabled...) So if your
system does build this one, then it is an issue for you.
If you don't build it, wonderful, not a problem! But we can't just not
assign a CVE just because someone might not build this file, again, we
do not know use cases, which is why we have to assign CVEs for all files
that could be built as part of a kernel image (but not for the userspace
test stuff.)
thanks,
greg k-h
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2024-06-13 13:59 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
[not found] <2024041704-CVE-2024-26831-2e6e@gregkh>
2024-06-11 8:21 ` CVE-2024-26831: net/handshake: Fix handshake_req_destroy_test1 Vegard Nossum
2024-06-13 13:59 ` Greg Kroah-Hartman
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®