Re: [PATCH 0/1] uas: add stream number sanity checks (maybe 6.1)

2021-08-23 Thread Peter Maydell
On Mon, 23 Aug 2021 at 10:59, Mauro Matteo Cascella wrote: > > Hi, > > On Fri, Aug 20, 2021 at 3:07 PM Philippe Mathieu-Daudé > wrote: > > > > Cc'ing Mauro to double-check. > > > > On 8/20/21 2:12 PM, Peter Maydell wrote: > > > On Wed, 18 Aug 2021 at 13:10, Gerd Hoffmann wrote: > > >> > > >> Sec

Re: [PATCH 0/1] uas: add stream number sanity checks (maybe 6.1)

2021-08-23 Thread Mauro Matteo Cascella
Hi, On Fri, Aug 20, 2021 at 3:07 PM Philippe Mathieu-Daudé wrote: > > Cc'ing Mauro to double-check. > > On 8/20/21 2:12 PM, Peter Maydell wrote: > > On Wed, 18 Aug 2021 at 13:10, Gerd Hoffmann wrote: > >> > >> Security fix. Sorry for the last-minute patch, I had completely > >> forgotten this o

Re: [PATCH 0/1] uas: add stream number sanity checks (maybe 6.1)

2021-08-20 Thread Philippe Mathieu-Daudé
Cc'ing Mauro to double-check. On 8/20/21 2:12 PM, Peter Maydell wrote: > On Wed, 18 Aug 2021 at 13:10, Gerd Hoffmann wrote: >> >> Security fix. Sorry for the last-minute patch, I had completely >> forgotten this one until the CVE number for it arrived today. >> >> Given that the classic usb stor

Re: [PATCH 0/1] uas: add stream number sanity checks (maybe 6.1)

2021-08-20 Thread Peter Maydell
On Wed, 18 Aug 2021 at 13:10, Gerd Hoffmann wrote: > > Security fix. Sorry for the last-minute patch, I had completely > forgotten this one until the CVE number for it arrived today. > > Given that the classic usb storage device is way more popular than > the uas (usb attached scsi) device the im

Re: [PATCH 0/1] uas: add stream number sanity checks (maybe 6.1)

2021-08-20 Thread Philippe Mathieu-Daudé
On 8/18/21 2:05 PM, Gerd Hoffmann wrote: > Security fix. Sorry for the last-minute patch, I had completely > forgotten this one until the CVE number for it arrived today. > > Given that the classic usb storage device is way more popular than > the uas (usb attached scsi) device the impact should

[PATCH 0/1] uas: add stream number sanity checks (maybe 6.1)

2021-08-18 Thread Gerd Hoffmann
Security fix. Sorry for the last-minute patch, I had completely forgotten this one until the CVE number for it arrived today. Given that the classic usb storage device is way more popular than the uas (usb attached scsi) device the impact should be pretty low and we might consider to not screw up