CVE-2016-10229: udp: properly support MSG_PEEK with truncated buffers#1097
Merged
Conversation
Add upstream patch to fix CVE-2016-10229
Member
|
Thanks, will merge after a quick build test. Fortunately, usual Gluon setups aren't affected, as none of the default packages use MSG_PEEK (the dnsmasq code contains one call, but it is in the DHCP component which is not active during the normal operation of a node). |
ecsv
pushed a commit
to FreifunkVogtland/gluon
that referenced
this pull request
Jun 9, 2017
…nk-gluon#1097) Add upstream patch to fix CVE-2016-10229
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Add upstream patch to fix CVE-2016-10229
This just adds a commit from upstream linux v3.18.45, which should fix CVE-2016-10229 (https://nvd.nist.gov/vuln/detail/CVE-2016-10229).
Before merging, this patch should get some testing. By now, I only checked that ar71xx-generic still builds - not even tried to flash the resulting firmware.
This patch may also be necessary for master (LEDE), if there are any relevant architectures still using 3.18. Architectures using 4.4 should be fine, as it contains the fix since v4.4.21.