Bugzilla – Full Text Bug Listing |
Summary: | VUL-0: CVE-2004-0003: kernel: DRI: 3 bugs | ||
---|---|---|---|
Product: | [Novell Products] SUSE Security Incidents | Reporter: | Andreas Schwab <schwab> |
Component: | Incidents | Assignee: | Thomas Biege <thomas> |
Status: | RESOLVED FIXED | QA Contact: | Security Team bot <security-team> |
Severity: | Normal | ||
Priority: | P3 - Medium | CC: | security-team |
Version: | unspecified | ||
Target Milestone: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | CVE-2004-0003: CVSS v2 Base Score: 4.6 (AV:L/AC:L/Au:N/C:P/I:P/A:P) | ||
Found By: | --- | Services Priority: | |
Business Priority: | Blocker: | --- | |
Marketing QA Status: | --- | IT Deployment: | --- |
Attachments: |
proposed patch from Alan
drm_r128_state.c.diff (drm subdirec) drm4_r128_state.c.diff (drm4 subdirec) |
Description
Thomas Biege
2004-01-14 17:35:10 UTC
<!-- SBZ_reproduce --> - Created attachment 15651 [details]
proposed patch from Alan
CAN-2004-0003 Fixed. <!-- SBZ_reopen -->Reopened by schwab@suse.de at Fri Feb 13 11:25:21 2004, took initial reporter thomas@suse.de to cc What if depth->n is negative? Looks like the patch is incomplete. Is depth->n signed? Otherwise it will not matter. Hm, but count is unsigned... so it can even be negativ if depth->n is a unsigned integer. *sigh* I will not stop the current kernel update for this. I think a fix in our kernel CVS should suffice here. I'll inform vendor-sec. Thanks Andreas. s/count is unsigned/count is signed/ I'll look into a patch this week. Created attachment 16028 [details]
drm_r128_state.c.diff (drm subdirec)
Created attachment 16029 [details]
drm4_r128_state.c.diff (drm4 subdirec)
Both patches were sent to vendor-sec@ yesterday. packages released. Found this bugreport with the help of the kernel changelog. Finally we got some feedback for this change. BTW, did anybody test this patch? I wonder why this guy is affected as the patch is only for the r128 DRM driver. Radeon 8000 sounds more like a Radeon chipset ... Date: Thu, 25 Mar 2004 15:39:14 +0100 From: juanignaciosl@yahoo.es Reply-To: STTS-FB <stts-fb@suse.de> To: jd@suse.de Subject: Ticket [20040322990000155] : "Upgrading the kernel causes the screen to freeze for a while" Summary: Upgrading the kernel causes the screen to freeze for a while Salutation: Mr. Language: english Name: Nacho Mail: juanignaciosl@yahoo.es Language: english Packagename: kernel update Component: Update Problems Productname: SUSE LINUX Versionname: SUSE LINUX 9.0 professional Platform: i386 Severity: Minor bug: Work is hindered unnecessarily Description hardware: Radeon 8000 Description how to reproduce: 1. How to reproduce: Upgrade the kernel to the one who corrected some DRI bugs (the one delivered past week, I can't remember the exact version). 2. This is not working: Screen output freeze for a moment (some miliseconds) apparently randomly. I realized playing Armagetron, but later I saw it +happens continously; for example, if I just move the mouse on the desktop it sometimes stops. This is particulary molest in +games. 3. Error messages and logfiles I have searched for errors or warnings in XFree log files, but there's nothing extrange there. No error message is displayed +on screen. CVE-2004-0003: CVSS v2 Base Score: 4.6 (AV:L/AC:L/Au:N/C:P/I:P/A:P) |