]> git.ipfire.org Git - thirdparty/kernel/stable-queue.git/commitdiff
2.6.25.15 and 2.6.26.2 releases
authorGreg Kroah-Hartman <gregkh@suse.de>
Wed, 6 Aug 2008 18:05:24 +0000 (11:05 -0700)
committerGreg Kroah-Hartman <gregkh@suse.de>
Wed, 6 Aug 2008 18:05:24 +0000 (11:05 -0700)
64 files changed:
releases/2.6.25.15/acpi-reject-below-freezing-temperatures-as-invalid-critical-temperatures.patch [moved from review-2.6.25/acpi-reject-below-freezing-temperatures-as-invalid-critical-temperatures.patch with 100% similarity]
releases/2.6.25.15/acpi-update-thermal-temperature.patch [moved from review-2.6.25/acpi-update-thermal-temperature.patch with 100% similarity]
releases/2.6.25.15/add-compat-handler-for-ptrace_getsiginfo.patch [moved from review-2.6.25/add-compat-handler-for-ptrace_getsiginfo.patch with 100% similarity]
releases/2.6.25.15/alsa-ac97-fix-asus-a9t-laptop-output.patch [moved from review-2.6.25/alsa-ac97-fix-asus-a9t-laptop-output.patch with 100% similarity]
releases/2.6.25.15/alsa-add-more-fallbacks-to-oss-phoneout-mixer-map.patch [moved from review-2.6.25/alsa-add-more-fallbacks-to-oss-phoneout-mixer-map.patch with 100% similarity]
releases/2.6.25.15/alsa-emu10k1-fix-inverted-analog-digital-mixer-switch-on-audigy2.patch [moved from review-2.6.25/alsa-emu10k1-fix-inverted-analog-digital-mixer-switch-on-audigy2.patch with 100% similarity]
releases/2.6.25.15/alsa-fix-oops-with-usb-audio-reconnection.patch [moved from review-2.6.25/alsa-fix-oops-with-usb-audio-reconnection.patch with 100% similarity]
releases/2.6.25.15/alsa-hda-add-missing-thinkpad-z60m-support.patch [moved from review-2.6.25/alsa-hda-add-missing-thinkpad-z60m-support.patch with 100% similarity]
releases/2.6.25.15/alsa-hda-fix-wrong-volumes-in-ad1988-auto-probe-mode.patch [moved from review-2.6.25/alsa-hda-fix-wrong-volumes-in-ad1988-auto-probe-mode.patch with 100% similarity]
releases/2.6.25.15/ath5k-use-software-encryption-for-now.patch [moved from review-2.6.25/ath5k-use-software-encryption-for-now.patch with 100% similarity]
releases/2.6.25.15/bay-exit-if-notify-handler-cannot-be-installed.patch [moved from review-2.6.25/bay-exit-if-notify-handler-cannot-be-installed.patch with 100% similarity]
releases/2.6.25.15/bluetooth-signal-user-space-for-hidp-and-bnep-socket-errors.patch [moved from review-2.6.25/bluetooth-signal-user-space-for-hidp-and-bnep-socket-errors.patch with 100% similarity]
releases/2.6.25.15/fat-detect-media-without-partition-table-correctly.patch [moved from review-2.6.25/fat-detect-media-without-partition-table-correctly.patch with 100% similarity]
releases/2.6.25.15/fat_valid_media-remove-pointless-test.patch [moved from review-2.6.25/fat_valid_media-remove-pointless-test.patch with 100% similarity]
releases/2.6.25.15/input-appletouch-implement-reset-resume-logic.patch [moved from review-2.6.25/input-appletouch-implement-reset-resume-logic.patch with 100% similarity]
releases/2.6.25.15/input-i8042-add-acer-aspire-1360-to-nomux-blacklist.patch [moved from review-2.6.25/input-i8042-add-acer-aspire-1360-to-nomux-blacklist.patch with 100% similarity]
releases/2.6.25.15/input-i8042-add-fujitsu-siemens-amilo-pro-2010-to-nomux-list.patch [moved from review-2.6.25/input-i8042-add-fujitsu-siemens-amilo-pro-2010-to-nomux-list.patch with 100% similarity]
releases/2.6.25.15/input-i8042-add-fujitsu-siemens-amilo-pro-v2030-to-nomux-table.patch [moved from review-2.6.25/input-i8042-add-fujitsu-siemens-amilo-pro-v2030-to-nomux-table.patch with 100% similarity]
releases/2.6.25.15/input-i8042-add-gericom-bellagio-to-nomux-blacklist.patch [moved from review-2.6.25/input-i8042-add-gericom-bellagio-to-nomux-blacklist.patch with 100% similarity]
releases/2.6.25.15/input-i8042-add-intel-d845pesv-to-nopnp-list.patch [moved from review-2.6.25/input-i8042-add-intel-d845pesv-to-nopnp-list.patch with 100% similarity]
releases/2.6.25.15/input-i8042-retry-failed-ctr-writes-when-resuming.patch [moved from review-2.6.25/input-i8042-retry-failed-ctr-writes-when-resuming.patch with 100% similarity]
releases/2.6.25.15/jbd-fix-possible-journal-overflow-issues.patch [moved from review-2.6.25/jbd-fix-possible-journal-overflow-issues.patch with 100% similarity]
releases/2.6.25.15/jbd-fix-race-between-free-buffer-and-commit-transaction.patch [moved from review-2.6.25/jbd-fix-race-between-free-buffer-and-commit-transaction.patch with 100% similarity]
releases/2.6.25.15/jbd-fix-the-way-the-b_modified-flag-is-cleared.patch [moved from review-2.6.25/jbd-fix-the-way-the-b_modified-flag-is-cleared.patch with 100% similarity]
releases/2.6.25.15/linux-2.6-x86-mm-ioremap-64-bit-resource-on-32-bit-kernel.patch [moved from review-2.6.25/linux-2.6-x86-mm-ioremap-64-bit-resource-on-32-bit-kernel.patch with 100% similarity]
releases/2.6.25.15/mbox [moved from review-2.6.25/mbox with 100% similarity]
releases/2.6.25.15/nfs-ensure-we-zap-only-the-access-and-acl-caches-when-setting-new-acls.patch [moved from review-2.6.25/nfs-ensure-we-zap-only-the-access-and-acl-caches-when-setting-new-acls.patch with 100% similarity]
releases/2.6.25.15/pci-vt3336-can-t-do-msi-either.patch [moved from review-2.6.25/pci-vt3336-can-t-do-msi-either.patch with 100% similarity]
releases/2.6.25.15/powerpc-ps3-add-time-include-to-lpm.patch [moved from review-2.6.25/powerpc-ps3-add-time-include-to-lpm.patch with 100% similarity]
releases/2.6.25.15/return-to-old-errno-choice-in-mkdir-et.al.patch [moved from review-2.6.25/return-to-old-errno-choice-in-mkdir-et.al.patch with 100% similarity]
releases/2.6.25.15/romfs_readpage-don-t-report-errors-for-pages-beyond-i_size.patch [moved from review-2.6.25/romfs_readpage-don-t-report-errors-for-pages-beyond-i_size.patch with 100% similarity]
releases/2.6.25.15/scsi-megaraid_mbox-fix-dell-cerc-firmware-problem.patch [moved from review-2.6.25/scsi-megaraid_mbox-fix-dell-cerc-firmware-problem.patch with 100% similarity]
releases/2.6.25.15/series [moved from review-2.6.25/series with 96% similarity]
releases/2.6.25.15/sound-ensure-device-number-is-valid-in-snd_seq_oss_synth_make_info.patch [new file with mode: 0644]
releases/2.6.25.15/usb-ehci-fix-remote-wakeup-regression.patch [moved from review-2.6.25/usb-ehci-fix-remote-wakeup-regression.patch with 100% similarity]
releases/2.6.25.15/vfs-fix-lookup-on-deleted-directory.patch [moved from review-2.6.25/vfs-fix-lookup-on-deleted-directory.patch with 100% similarity]
releases/2.6.26.2/add-compat-handler-for-ptrace_getsiginfo.patch [moved from review-2.6.26/add-compat-handler-for-ptrace_getsiginfo.patch with 100% similarity]
releases/2.6.26.2/alsa-emu10k1-fix-inverted-analog-digital-mixer-switch-on-audigy2.patch [moved from review-2.6.26/alsa-emu10k1-fix-inverted-analog-digital-mixer-switch-on-audigy2.patch with 100% similarity]
releases/2.6.26.2/alsa-hda-add-missing-thinkpad-z60m-support.patch [moved from review-2.6.26/alsa-hda-add-missing-thinkpad-z60m-support.patch with 100% similarity]
releases/2.6.26.2/alsa-hda-fix-dma-position-inaccuracy.patch [moved from review-2.6.26/alsa-hda-fix-dma-position-inaccuracy.patch with 100% similarity]
releases/2.6.26.2/alsa-hda-fix-wrong-volumes-in-ad1988-auto-probe-mode.patch [moved from review-2.6.26/alsa-hda-fix-wrong-volumes-in-ad1988-auto-probe-mode.patch with 100% similarity]
releases/2.6.26.2/ath5k-fix-memory-corruption.patch [moved from review-2.6.26/ath5k-fix-memory-corruption.patch with 100% similarity]
releases/2.6.26.2/ath5k-kill-tasklets-on-shutdown.patch [moved from review-2.6.26/ath5k-kill-tasklets-on-shutdown.patch with 100% similarity]
releases/2.6.26.2/bluetooth-signal-user-space-for-hidp-and-bnep-socket-errors.patch [moved from review-2.6.26/bluetooth-signal-user-space-for-hidp-and-bnep-socket-errors.patch with 100% similarity]
releases/2.6.26.2/close-race-in-md_probe.patch [moved from review-2.6.26/close-race-in-md_probe.patch with 100% similarity]
releases/2.6.26.2/ftrace-remove-unneeded-documentation.patch [moved from review-2.6.26/ftrace-remove-unneeded-documentation.patch with 100% similarity]
releases/2.6.26.2/input-i8042-add-acer-aspire-1360-to-nomux-blacklist.patch [moved from review-2.6.26/input-i8042-add-acer-aspire-1360-to-nomux-blacklist.patch with 100% similarity]
releases/2.6.26.2/input-i8042-add-gericom-bellagio-to-nomux-blacklist.patch [moved from review-2.6.26/input-i8042-add-gericom-bellagio-to-nomux-blacklist.patch with 100% similarity]
releases/2.6.26.2/input-i8042-add-intel-d845pesv-to-nopnp-list.patch [moved from review-2.6.26/input-i8042-add-intel-d845pesv-to-nopnp-list.patch with 100% similarity]
releases/2.6.26.2/jbd-fix-race-between-free-buffer-and-commit-transaction.patch [moved from review-2.6.26/jbd-fix-race-between-free-buffer-and-commit-transaction.patch with 100% similarity]
releases/2.6.26.2/kprobe-smoke-test-lockdep-warning.patch [moved from review-2.6.26/kprobe-smoke-test-lockdep-warning.patch with 100% similarity]
releases/2.6.26.2/linear-correct-disk-numbering-error-check.patch [moved from review-2.6.26/linear-correct-disk-numbering-error-check.patch with 100% similarity]
releases/2.6.26.2/mbox [moved from review-2.6.26/mbox with 100% similarity]
releases/2.6.26.2/netfilter-nf_nat_sip-c-is-optional-for-session.patch [moved from review-2.6.26/netfilter-nf_nat_sip-c-is-optional-for-session.patch with 100% similarity]
releases/2.6.26.2/netfilter-xt_time-fix-time-s-time_mt-s-use-of-do_div.patch [moved from review-2.6.26/netfilter-xt_time-fix-time-s-time_mt-s-use-of-do_div.patch with 100% similarity]
releases/2.6.26.2/nfs-ensure-we-zap-only-the-access-and-acl-caches-when-setting-new-acls.patch [moved from review-2.6.26/nfs-ensure-we-zap-only-the-access-and-acl-caches-when-setting-new-acls.patch with 100% similarity]
releases/2.6.26.2/romfs_readpage-don-t-report-errors-for-pages-beyond-i_size.patch [moved from review-2.6.26/romfs_readpage-don-t-report-errors-for-pages-beyond-i_size.patch with 100% similarity]
releases/2.6.26.2/scsi-bsg-fix-bsg_mutex-hang-with-device-removal.patch [moved from review-2.6.26/scsi-bsg-fix-bsg_mutex-hang-with-device-removal.patch with 100% similarity]
releases/2.6.26.2/scsi-ch-fix-ch_remove-oops.patch [moved from review-2.6.26/scsi-ch-fix-ch_remove-oops.patch with 100% similarity]
releases/2.6.26.2/series [moved from review-2.6.26/series with 94% similarity]
releases/2.6.26.2/sound-ensure-device-number-is-valid-in-snd_seq_oss_synth_make_info.patch [new file with mode: 0644]
releases/2.6.26.2/vfs-fix-lookup-on-deleted-directory.patch [moved from review-2.6.26/vfs-fix-lookup-on-deleted-directory.patch with 100% similarity]
releases/2.6.26.2/x86-idle-process-add-checking-for-null-early-param.patch [moved from review-2.6.26/x86-idle-process-add-checking-for-null-early-param.patch with 100% similarity]
releases/2.6.26.2/x86-io-delay-add-checking-for-null-early-param.patch [moved from review-2.6.26/x86-io-delay-add-checking-for-null-early-param.patch with 100% similarity]

similarity index 100%
rename from review-2.6.25/mbox
rename to releases/2.6.25.15/mbox
similarity index 96%
rename from review-2.6.25/series
rename to releases/2.6.25.15/series
index e0a2425ecc18f8dd922809381b791f92bb094e24..ec964938f9819f0b2f71e2354098829e57084c29 100644 (file)
@@ -31,3 +31,4 @@ alsa-fix-oops-with-usb-audio-reconnection.patch
 alsa-hda-add-missing-thinkpad-z60m-support.patch
 alsa-hda-fix-wrong-volumes-in-ad1988-auto-probe-mode.patch
 vfs-fix-lookup-on-deleted-directory.patch
+sound-ensure-device-number-is-valid-in-snd_seq_oss_synth_make_info.patch
diff --git a/releases/2.6.25.15/sound-ensure-device-number-is-valid-in-snd_seq_oss_synth_make_info.patch b/releases/2.6.25.15/sound-ensure-device-number-is-valid-in-snd_seq_oss_synth_make_info.patch
new file mode 100644 (file)
index 0000000..e2ac857
--- /dev/null
@@ -0,0 +1,38 @@
+From stable-bounces@linux.kernel.org Mon Aug  4 17:20:12 2008
+From: Willy Tarreau <w@1wt.eu>
+Date: Tue, 5 Aug 2008 00:20:03 GMT
+Subject: sound: ensure device number is valid in snd_seq_oss_synth_make_info
+To: jejb@kernel.org, stable@kernel.org
+Message-ID: <200808050020.m750K3ii020082@hera.kernel.org>
+
+From: Willy Tarreau <w@1wt.eu>
+
+commit 82e68f7ffec3800425f2391c8c86277606860442 upstream
+
+snd_seq_oss_synth_make_info() incorrectly reports information
+to userspace without first checking for the validity of the
+device number, leading to possible information leak (CVE-2008-3272).
+
+Reported-By: Tobias Klein <tk@trapkit.de>
+Acked-and-tested-by: Takashi Iwai <tiwai@suse.de>
+Cc: stable@kernel.org
+Signed-off-by: Willy Tarreau <w@1wt.eu>
+Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
+Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
+
+---
+ sound/core/seq/oss/seq_oss_synth.c |    3 +++
+ 1 file changed, 3 insertions(+)
+
+--- a/sound/core/seq/oss/seq_oss_synth.c
++++ b/sound/core/seq/oss/seq_oss_synth.c
+@@ -599,6 +599,9 @@ snd_seq_oss_synth_make_info(struct seq_o
+ {
+       struct seq_oss_synth *rec;
++      if (dev < 0 || dev >= dp->max_synthdev)
++              return -ENXIO;
++
+       if (dp->synths[dev].is_midi) {
+               struct midi_info minf;
+               snd_seq_oss_midi_make_info(dp, dp->synths[dev].midi_mapped, &minf);
similarity index 100%
rename from review-2.6.26/mbox
rename to releases/2.6.26.2/mbox
similarity index 94%
rename from review-2.6.26/series
rename to releases/2.6.26.2/series
index abb9534669e4ce1fc1f57c0d44632ff46b8a0fd3..31167bff8bf936cdc76935a895e909345bef2f4c 100644 (file)
@@ -23,3 +23,4 @@ alsa-emu10k1-fix-inverted-analog-digital-mixer-switch-on-audigy2.patch
 vfs-fix-lookup-on-deleted-directory.patch
 ath5k-fix-memory-corruption.patch
 ath5k-kill-tasklets-on-shutdown.patch
+sound-ensure-device-number-is-valid-in-snd_seq_oss_synth_make_info.patch
diff --git a/releases/2.6.26.2/sound-ensure-device-number-is-valid-in-snd_seq_oss_synth_make_info.patch b/releases/2.6.26.2/sound-ensure-device-number-is-valid-in-snd_seq_oss_synth_make_info.patch
new file mode 100644 (file)
index 0000000..57617c7
--- /dev/null
@@ -0,0 +1,38 @@
+From stable-bounces@linux.kernel.org Mon Aug  4 17:20:12 2008
+From: Willy Tarreau <w@1wt.eu>
+Date: Tue, 5 Aug 2008 00:20:03 GMT
+Subject: sound: ensure device number is valid in snd_seq_oss_synth_make_info
+To: jejb@kernel.org, stable@kernel.org
+Message-ID: <200808050020.m750K3ii020082@hera.kernel.org>
+
+From: Willy Tarreau <w@1wt.eu>
+
+commit 82e68f7ffec3800425f2391c8c86277606860442 upstream
+
+snd_seq_oss_synth_make_info() incorrectly reports information
+to userspace without first checking for the validity of the
+device number, leading to possible information leak (CVE-2008-3272).
+
+Reported-By: Tobias Klein <tk@trapkit.de>
+Acked-and-tested-by: Takashi Iwai <tiwai@suse.de>
+Cc: stable@kernel.org
+Signed-off-by: Willy Tarreau <w@1wt.eu>
+Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
+Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
+
+---
+ sound/core/seq/oss/seq_oss_synth.c |    3 +++
+ 1 file changed, 3 insertions(+)
+
+--- a/sound/core/seq/oss/seq_oss_synth.c
++++ b/sound/core/seq/oss/seq_oss_synth.c
+@@ -604,6 +604,9 @@ snd_seq_oss_synth_make_info(struct seq_o
+ {
+       struct seq_oss_synth *rec;
++      if (dev < 0 || dev >= dp->max_synthdev)
++              return -ENXIO;
++
+       if (dp->synths[dev].is_midi) {
+               struct midi_info minf;
+               snd_seq_oss_midi_make_info(dp, dp->synths[dev].midi_mapped, &minf);