Public bug reported:

Hello Ubuntu team,

The current vmw_vsock_vmci_transport driver in older kernels may contain
an information disclosure vulnerability due to the usage of an
uninitialized memory in vSockets.

Fix Commit(s):

 Commit Id:- 223e2288f4b8
 Description:- Fix vsock/vmci: Clear the vmci transport packet properly when 
initializing it
 Upstream version:- 6.16
 Link:- 
https://git.kernel.org/pub/scm/linux/kernel/git/netdev/net.git/commit/?id=223e2288f4b8

We respectfully request that the updates to the vmw_vsock_vmci_transport
driver be backported to the next Ubuntu 22.04 release. These update
addresses a security issue.

Thank you for your support.

** Affects: linux (Ubuntu)
     Importance: Undecided
         Status: New

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2119708

Title:
  Backport Request: vmw_vsock_vmci_transport (Version: 1.0.5.0-k) to
  Ubuntu 22.04

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2119708/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to