stable.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* Fix for CVE-2016-7097 missing from linux-4.1.y
@ 2016-11-10 22:59 Josh Hunt
  2016-11-11  9:58 ` Jan Kara
  0 siblings, 1 reply; 5+ messages in thread
From: Josh Hunt @ 2016-11-10 22:59 UTC (permalink / raw)
  To: jack; +Cc: Levin, Alexander, stable@vger.kernel.org

Hi Jan

You are the author of commit 073931017b49 ("posix_acl: Clear SGID bit 
when setting file permissions") which has been identified to resolve 
CVE-2016-7097, but is missing from linux-4.1.y.

If you believe this commit should be part of linux-4.1.y can you please 
reply with your approval for its inclusion?

Thanks!
Josh

P.S.: This is my first attempt at trying to make sure all known CVE 
fixes are in the stable kernels. After a discussion with Sasha at 
Plumbers I'd like to start doing this on a regular basis. Any feedback 
here is welcome.

---
Full list of CVEs associated with 4.1.y can be found here:
http://joshuahunt.github.io/cve-tracker/linux-4.1.y-stable-cve-list.html


^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2016-11-16 18:01 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2016-11-10 22:59 Fix for CVE-2016-7097 missing from linux-4.1.y Josh Hunt
2016-11-11  9:58 ` Jan Kara
2016-11-12  3:03   ` Ben Hutchings
2016-11-16 17:56     ` Josh Hunt
2016-11-16 18:00       ` Ben Hutchings

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).