All of lore.kernel.org
 help / color / mirror / Atom feed
* Security fixes for 4.9
@ 2018-12-06 14:19 Ben Hutchings
  2018-12-06 14:28 ` Greg Kroah-Hartman
  0 siblings, 1 reply; 4+ messages in thread
From: Ben Hutchings @ 2018-12-06 14:19 UTC (permalink / raw)
  To: Greg Kroah-Hartman, Sasha Levin; +Cc: stable

[-- Attachment #1: Type: text/plain, Size: 637 bytes --]

I've backported a number of fixes for security issues affecting 4.9-
stable.  All of these are already fixed in 4.14-stable and 4.19-stable.

Most of the issues involve filesystem validation, and I tested with the
reproducers where available.

For the BPF fix, I verified that the self-tests (taken from 4.14)
didn't regress and temporarily added logging to check that the
mitigation is applied when needed.

Ben.

-- 
Ben Hutchings, Software Developer                         Codethink Ltd
https://www.codethink.co.uk/                 Dale House, 35 Dale Street
                                     Manchester, M1 2HF, United Kingdom

[-- Attachment #2: security-4.9.mbox --]
[-- Type: application/mbox, Size: 300634 bytes --]

^ permalink raw reply	[flat|nested] 4+ messages in thread
* Security fixes for 4.9
@ 2017-11-15 16:55 Ben Hutchings
  2017-11-15 18:00 ` Greg Kroah-Hartman
  0 siblings, 1 reply; 4+ messages in thread
From: Ben Hutchings @ 2017-11-15 16:55 UTC (permalink / raw)
  To: Greg Kroah-Hartman; +Cc: stable

Please cherry-pick the following commits for 4.9-stable:

fdf7cb4185b6 mac80211: accept key reinstall without changing anything
2bdd713b92a9 mac80211: use constant time comparison with keys
cfbb0d90a7ab mac80211: don't compare TKIP TX MIC key in reinstall prevention
fc27fe7e8dee ALSA: seq: Cancel pending autoload work at unbinding device
7c80f9e4a588 usb: usbtest: fix NULL pointer dereference
ea04efee7635 Input: ims-psu - check if CDC union descriptor is sane

For the ALSA seq fix, you'll need to change the patched filename from
sound/core/seq_device.c to sound/core/seq/seq_device.c.  The rest
should apply cleanly.

Ben.

-- 
Ben Hutchings
Software Developer, Codethink Ltd.

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2018-12-06 14:30 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2018-12-06 14:19 Security fixes for 4.9 Ben Hutchings
2018-12-06 14:28 ` Greg Kroah-Hartman
  -- strict thread matches above, loose matches on Subject: below --
2017-11-15 16:55 Ben Hutchings
2017-11-15 18:00 ` Greg Kroah-Hartman

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.