|
Bugzilla – Full Text Bug Listing |
| Summary: | VUL-0: kernel: CONFIG_AUDITSYSCALL memleak | ||
|---|---|---|---|
| Product: | [openSUSE] SUSE LINUX 10.0 | Reporter: | Thomas Biege <thomas> |
| Component: | Kernel | Assignee: | Marcus Meissner <meissner> |
| Status: | RESOLVED FIXED | QA Contact: | E-mail List <qa-bugs> |
| Severity: | Normal | ||
| Priority: | P5 - None | CC: | patch-request, security-team |
| Version: | unspecified | ||
| Target Milestone: | --- | ||
| Hardware: | Other | ||
| OS: | All | ||
| Whiteboard: | CVE-2005-3181: CVSS v2 Base Score: 2.1 (AV:L/AC:L/Au:N/C:N/I:N/A:P) | ||
| Found By: | Other | Services Priority: | |
| Business Priority: | Blocker: | --- | |
| Marketing QA Status: | --- | IT Deployment: | --- |
| Attachments: | auditfs-leak.patch | ||
|
Description
Thomas Biege
2005-10-10 10:28:55 UTC
for 10.0 Created attachment 52083 [details]
auditfs-leak.patch
hubert for 10.0 only. please apply Candidate: CAN-2005-3181 URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-3181 Reference: CONFIRM:http://linux.bkbits.net:8080/linux-2.6/cset@4346883bQBeBd26syWTKX2CVC5bDcA Linux kernel 2.6.13 and earlier, when CONFIG_AUDITSYSCALL is enabled, uses an incorrect function to free names_cache memory, which prevents the memory from being tracked by AUDITSYSCALL code and leads to a memory leak. still needs applier for 10.0 -> mason day.. Ack, This will go in on Monday. Marcus, comment #2 confuses me, does it really belong with this patch? comment #2 is bad and is the wrong patch, sorry... do you need the patch extracted? This is now in cvs, sorry for the delay. thanks! assigning back to us for tracking. updates released for 10.0. CVE-2005-3181: CVSS v2 Base Score: 2.1 (AV:L/AC:L/Au:N/C:N/I:N/A:P) |