Module Name: src
Committed By: snj
Date: Sat Sep 9 16:54:15 UTC 2017
Modified Files:
src/doc [netbsd-6-1]: CHANGES-6.1.6
Log Message:
1502
To generate a diff of this commit:
cvs rdiff -u -r1.1.2.112 -r1.1.2.113 src/doc/CHANGES-6.1.6
Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.
Modified files:
Index: src/doc/CHANGES-6.1.6
diff -u src/doc/CHANGES-6.1.6:1.1.2.112 src/doc/CHANGES-6.1.6:1.1.2.113
--- src/doc/CHANGES-6.1.6:1.1.2.112 Mon Sep 4 16:04:59 2017
+++ src/doc/CHANGES-6.1.6 Sat Sep 9 16:54:15 2017
@@ -1,4 +1,4 @@
-# $NetBSD: CHANGES-6.1.6,v 1.1.2.112 2017/09/04 16:04:59 snj Exp $
+# $NetBSD: CHANGES-6.1.6,v 1.1.2.113 2017/09/09 16:54:15 snj Exp $
A complete list of changes from the NetBSD 6.1.5 release to the NetBSD 6.1.6
release:
@@ -14805,3 +14805,11 @@ sys/arch/sparc64/sparc64/compat_13_machd
in %pstate and get kernel privileges on the hardware.
[maxv, ticket #1501]
+sys/compat/linux32/arch/amd64/linux32_machdep.c 1.39
+
+
+ Fix a ring0 escalation vulnerability in compat_linux32 where the
+ index of %cs is controlled by userland, making it easy to trigger
+ the page fault and get kernel privileges.
+ [maxv, ticket #1502]
+