We have moved to a new Sailfish OS Forum. Please start new discussions there.

Revision history [back]

click to hide/show revision 1
initial version

posted 2017-07-20 11:41:22 +0300

verify the underlying transport exists before creating a connection in kernel-rds CVE-2015-6937 remote

The __rds_conn_create function in net/rds/connection.c in the Linux kernel through 4.2.3 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by using a socket that was not properly bound.

Upstream-commit and 3.2-backport are the same, so implementing in kernel-3.4 for jolla1 should be no problem...

file affected: kernel-adaptation-sbj-3.4.108.20161101.1/net/rds/connection.c lines 178-183

verify the underlying transport exists before creating a connection in kernel-rds CVE-2015-6937 remote

The __rds_conn_create function in net/rds/connection.c in the Linux kernel through 4.2.3 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by using a socket that was not properly bound.bound. CVSS v2 Base Score: 7.8 HIGH (attack range: remote)

Upstream-commit and 3.2-backport are the same, so implementing in kernel-3.4 for jolla1 should be no problem...

file affected: kernel-adaptation-sbj-3.4.108.20161101.1/net/rds/connection.c lines 178-183

verify the underlying transport exists before creating a connection in kernel-rds CVE-2015-6937 remote

The __rds_conn_create function in net/rds/connection.c in the Linux kernel through 4.2.3 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by using a socket that was not properly bound. CVSS v2 Base Score: 7.8 HIGH (attack range: remote)

Upstream-commit and 3.2-backport are the same, so implementing in kernel-3.4 for jolla1 should be no problem...

file File affected: kernel-adaptation-sbj-3.4.108.20161101.1/net/rds/connection.c lines 178-183

verify the underlying transport exists before creating a connection in kernel-rds CVE-2015-6937 remote

The __rds_conn_create function in net/rds/connection.c in the Linux kernel through 4.2.3 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by using a socket that was not properly bound. CVSS v2 Base Score: 7.8 HIGH (attack range: remote)

Upstream-commit and 3.2-backport are the same, equal, so implementing in kernel-3.4 for jolla1 should be no problem...problem ...

File affected: kernel-adaptation-sbj-3.4.108.20161101.1/net/rds/connection.c lines 178-183