From: "Michael S. Tsirkin" <[email protected]> Date: Thu, 27 Mar 2014 12:53:37 +0200
> vhost fails to validate negative error code > from vhost_get_vq_desc causing > a crash: we are using -EFAULT which is 0xfffffff2 > as vector size, which exceeds the allocated size. > > The code in question was introduced in commit > 8dd014adfea6f173c1ef6378f7e5e7924866c923 > vhost-net: mergeable buffers support > > CVE-2014-0055 > > Signed-off-by: Michael S. Tsirkin <[email protected]> > --- > > This is needed in -stable. Applied and queued up for -stable, thanks Michael. -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to [email protected] More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/

