Bugzilla – Bug 919655
VUL-0: CVE-2015-0274: kernel: xfs: Unprivileged local user can leak kernel memory
Last modified: 2017-09-20 14:47:46 UTC
bugbot adjusting priority
Yeah, this affects only kernels between 3.11 and 3.14 (inclusive). SLE12 branch already has the fix, and 13.2 kernel has the fix from upstream. So the only branch missing the fix is openSUSE-13.1. I'll take care of pushing the fix there.
OK, pushed the fix to openSUSE-13.1 branch.
public now.
AFAICT this can be closed. We have the patch in all the relevant branches. Marcus?
Closing the bug since the patch is everywhere for over two months.
In SLE12 branch: patches.fixes/xfs-remote-attribute-overwrite-causes-transaction-o.patch commit 72b7a0cf0cee4d8e4107fbb9e6db39a51943bc61 Author: Jan Kara <jack@suse.cz> Date: Thu May 22 19:23:36 2014 +0200 xfs: remote attribute overwrite causes transaction overrun. -> This was fixed before the release.
perl bin/addnote CVE-2015-0274 "This issue affected Linux Kernel 3.11 up to 3.14. The SUSE Linux Enterprise 12 kernel was fixed before the GA shipment. Older SUSE Linux Enterprise versions are not affected."