** Description changed:

- [forbid uaddr == uaddr2 in futex_wait_requeue_pi() to avoid null
- dereference]
+ The futex_wait_requeue_pi function in kernel/futex.c in the Linux kernel
+ before 3.5.1 does not ensure that calls have two different futex
+ addresses, which allows local users to cause a denial of service (NULL
+ pointer dereference and system crash) or possibly have unspecified other
+ impact via a crafted FUTEX_WAIT_REQUEUE_PI command.
  
  Break-Fix: 52400ba946759af28442dee6265c5c0180ac7122
  6f7b0a2a5c0fb03be7c25bd1745baa50582348ef

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1321452

Title:
  CVE-2012-6647

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1321452/+subscriptions

-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to