From: "Michael S. Tsirkin" <[email protected]>
Date: Thu, 27 Mar 2014 12:53:37 +0200

> vhost fails to validate negative error code
> from vhost_get_vq_desc causing
> a crash: we are using -EFAULT which is 0xfffffff2
> as vector size, which exceeds the allocated size.
> 
> The code in question was introduced in commit
> 8dd014adfea6f173c1ef6378f7e5e7924866c923
>     vhost-net: mergeable buffers support
> 
> CVE-2014-0055
> 
> Signed-off-by: Michael S. Tsirkin <[email protected]>
> ---
> 
> This is needed in -stable.

Applied and queued up for -stable, thanks Michael.
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to [email protected]
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

Reply via email to