[Bug 1298119] Re: CVE-2014-0131

2014-04-25 Thread John Johansen
** Also affects: linux (Ubuntu Utopic) Importance: Medium Status: Invalid ** Also affects: linux-fsl-imx51 (Ubuntu Utopic) Importance: Medium Status: Invalid ** Also affects: linux-mvl-dove (Ubuntu Utopic) Importance: Medium Status: Invalid ** Also affects: linux-ec

[Bug 1271442] Re: CVE-2014-1444

2014-04-25 Thread John Johansen
** Also affects: linux (Ubuntu Utopic) Importance: Low Status: Invalid ** Also affects: linux-fsl-imx51 (Ubuntu Utopic) Importance: Low Status: Invalid ** Also affects: linux-mvl-dove (Ubuntu Utopic) Importance: Low Status: Invalid ** Also affects: linux-ec2 (Ubuntu

[Bug 1295090] Re: CVE-2014-2523

2014-04-25 Thread John Johansen
** Also affects: linux (Ubuntu Utopic) Importance: Medium Status: Fix Committed ** Also affects: linux-fsl-imx51 (Ubuntu Utopic) Importance: Medium Status: Invalid ** Also affects: linux-mvl-dove (Ubuntu Utopic) Importance: Medium Status: Invalid ** Also affects: li

[Bug 1293726] Re: CVE-2014-2309

2014-04-25 Thread John Johansen
** Also affects: linux (Ubuntu Utopic) Importance: Medium Status: Invalid ** Also affects: linux-fsl-imx51 (Ubuntu Utopic) Importance: Medium Status: Invalid ** Also affects: linux-mvl-dove (Ubuntu Utopic) Importance: Medium Status: Invalid ** Also affects: linux-ec

[Bug 1271444] Re: CVE-2014-1445

2014-04-25 Thread John Johansen
** Also affects: linux (Ubuntu Utopic) Importance: Low Status: Invalid ** Also affects: linux-fsl-imx51 (Ubuntu Utopic) Importance: Low Status: Invalid ** Also affects: linux-mvl-dove (Ubuntu Utopic) Importance: Low Status: Invalid ** Also affects: linux-ec2 (Ubuntu

[Bug 1297743] Re: CVE-2014-2568

2014-04-25 Thread John Johansen
** Also affects: linux (Ubuntu Utopic) Importance: Medium Status: New ** Also affects: linux-fsl-imx51 (Ubuntu Utopic) Importance: Medium Status: Invalid ** Also affects: linux-mvl-dove (Ubuntu Utopic) Importance: Medium Status: Invalid ** Also affects: linux-ec2 (U

[Bug 1302222] Re: CVE-2014-2678

2014-04-25 Thread John Johansen
** Also affects: linux (Ubuntu Utopic) Importance: Medium Status: Fix Released ** Also affects: linux-fsl-imx51 (Ubuntu Utopic) Importance: Medium Status: Invalid ** Also affects: linux-mvl-dove (Ubuntu Utopic) Importance: Medium Status: Invalid ** Also affects: lin

[Bug 1302219] Re: CVE-2014-2673

2014-04-25 Thread John Johansen
** Also affects: linux (Ubuntu Utopic) Importance: Medium Status: Invalid ** Also affects: linux-fsl-imx51 (Ubuntu Utopic) Importance: Medium Status: Invalid ** Also affects: linux-mvl-dove (Ubuntu Utopic) Importance: Medium Status: Invalid ** Also affects: linux-ec

[Bug 1302212] Re: CVE-2014-2672

2014-04-25 Thread John Johansen
** Also affects: linux (Ubuntu Utopic) Importance: Medium Status: Invalid ** Also affects: linux-fsl-imx51 (Ubuntu Utopic) Importance: Medium Status: Invalid ** Also affects: linux-mvl-dove (Ubuntu Utopic) Importance: Medium Status: Invalid ** Also affects: linux-ec

[Bug 1306286] Re: CVE-2014-2739

2014-04-25 Thread John Johansen
** Also affects: linux (Ubuntu Utopic) Importance: Medium Status: New ** Also affects: linux-fsl-imx51 (Ubuntu Utopic) Importance: Medium Status: Invalid ** Also affects: linux-mvl-dove (Ubuntu Utopic) Importance: Medium Status: Invalid ** Also affects: linux-ec2 (U

[Bug 1302225] Re: CVE-2014-2706

2014-04-25 Thread John Johansen
** Also affects: linux (Ubuntu Utopic) Importance: Medium Status: Invalid ** Also affects: linux-fsl-imx51 (Ubuntu Utopic) Importance: Medium Status: Invalid ** Also affects: linux-mvl-dove (Ubuntu Utopic) Importance: Medium Status: Invalid ** Also affects: linux-ec

[Bug 1306286] Re: CVE-2014-2739

2014-04-25 Thread John Johansen
** Changed in: linux-armadaxp (Ubuntu Precise) Status: New => Invalid ** Changed in: linux-armadaxp (Ubuntu Quantal) Status: New => Invalid ** Changed in: linux-ec2 (Ubuntu Lucid) Status: New => Invalid ** Changed in: linux-lts-quantal (Ubuntu Precise) Status: New =>

[Bug 1312979] [NEW] CVE-2014-0077

2014-04-25 Thread John Johansen
*** This bug is a security vulnerability *** Public security bug reported: drivers/vhost/net.c in the Linux kernel before 3.13.10, when mergeable buffers are disabled, does not properly validate packet lengths, which allows guest OS users to cause a denial of service (memory corruption and host O

[Bug 1312979] Re: CVE-2014-0077

2014-04-25 Thread John Johansen
CVE-2014-0077 ** Also affects: linux (Ubuntu Utopic) Importance: Undecided Status: New ** Also affects: linux-fsl-imx51 (Ubuntu Utopic) Importance: Undecided Status: New ** Also affects: linux-mvl-dove (Ubuntu Utopic) Importance: Undecided Status: New ** Also affec

[Bug 1312980] [NEW] CVE-2014-0077

2014-04-25 Thread John Johansen
*** This bug is a security vulnerability *** Public security bug reported: drivers/vhost/net.c in the Linux kernel before 3.13.10, when mergeable buffers are disabled, does not properly validate packet lengths, which allows guest OS users to cause a denial of service (memory corruption and host O

[Bug 1312980] Re: CVE-2014-0077

2014-04-25 Thread John Johansen
CVE-2014-0077 ** Also affects: linux (Ubuntu Utopic) Importance: Undecided Status: New ** Also affects: linux-fsl-imx51 (Ubuntu Utopic) Importance: Undecided Status: New ** Also affects: linux-mvl-dove (Ubuntu Utopic) Importance: Undecided Status: New ** Also affec

[Bug 1312981] [NEW] CVE-2014-0077

2014-04-25 Thread John Johansen
*** This bug is a security vulnerability *** Public security bug reported: drivers/vhost/net.c in the Linux kernel before 3.13.10, when mergeable buffers are disabled, does not properly validate packet lengths, which allows guest OS users to cause a denial of service (memory corruption and host O

[Bug 1312981] Re: CVE-2014-0077

2014-04-25 Thread John Johansen
CVE-2014-0077 ** Also affects: linux (Ubuntu Utopic) Importance: Undecided Status: New ** Also affects: linux-fsl-imx51 (Ubuntu Utopic) Importance: Undecided Status: New ** Also affects: linux-mvl-dove (Ubuntu Utopic) Importance: Undecided Status: New ** Also affec

[Bug 1312984] Re: CVE-2014-0077

2014-04-25 Thread John Johansen
CVE-2014-0077 ** Also affects: linux (Ubuntu Utopic) Importance: Undecided Status: New ** Also affects: linux-fsl-imx51 (Ubuntu Utopic) Importance: Undecided Status: New ** Also affects: linux-mvl-dove (Ubuntu Utopic) Importance: Undecided Status: New ** Also affec

[Bug 1312984] [NEW] CVE-2014-0077

2014-04-25 Thread John Johansen
*** This bug is a security vulnerability *** Public security bug reported: drivers/vhost/net.c in the Linux kernel before 3.13.10, when mergeable buffers are disabled, does not properly validate packet lengths, which allows guest OS users to cause a denial of service (memory corruption and host O

[Bug 1312987] [NEW] CVE-2014-0155

2014-04-25 Thread John Johansen
*** This bug is a security vulnerability *** Public security bug reported: The ioapic_deliver function in virt/kvm/ioapic.c in the Linux kernel through 3.14.1 does not properly validate the kvm_irq_delivery_to_apic return value, which allows guest OS users to cause a denial of service (host OS cr

[Bug 1312987] Re: CVE-2014-0155

2014-04-25 Thread John Johansen
CVE-2014-0155 ** Also affects: linux (Ubuntu Utopic) Importance: Undecided Status: New ** Also affects: linux-fsl-imx51 (Ubuntu Utopic) Importance: Undecided Status: New ** Also affects: linux-mvl-dove (Ubuntu Utopic) Importance: Undecided Status: New ** Also affec

[Bug 1312989] [NEW] CVE-2014-0181

2014-04-25 Thread John Johansen
*** This bug is a security vulnerability *** Public security bug reported: It is possible, by passing a netlink socket to a more privileged executable and then fooling that executable into writing to the socket data that happens to be valid netlink message, to do something that privileged executa

[Bug 1312989] Re: CVE-2014-0181

2014-04-25 Thread John Johansen
CVE-2014-0181 ** Also affects: linux (Ubuntu Utopic) Importance: Undecided Status: New ** Also affects: linux-fsl-imx51 (Ubuntu Utopic) Importance: Undecided Status: New ** Also affects: linux-mvl-dove (Ubuntu Utopic) Importance: Undecided Status: New ** Also affec

[Bug 1312990] [NEW] CVE-2014-2851

2014-04-25 Thread John Johansen
*** This bug is a security vulnerability *** Public security bug reported: Integer overflow in the ping_init_sock function in net/ipv4/ping.c in the Linux kernel through 3.14.1 allows local users to cause a denial of service (use-after-free and system crash) or possibly gain privileges via a craf

[Bug 1312990] Re: CVE-2014-2851

2014-04-25 Thread John Johansen
CVE-2014-2851 ** Also affects: linux (Ubuntu Utopic) Importance: Undecided Status: New ** Also affects: linux-fsl-imx51 (Ubuntu Utopic) Importance: Undecided Status: New ** Also affects: linux-mvl-dove (Ubuntu Utopic) Importance: Undecided Status: New ** Also affec

[Bug 1312991] Re: CVE-2014-2851

2014-04-25 Thread John Johansen
CVE-2014-2851 ** Also affects: linux (Ubuntu Utopic) Importance: Undecided Status: New ** Also affects: linux-fsl-imx51 (Ubuntu Utopic) Importance: Undecided Status: New ** Also affects: linux-mvl-dove (Ubuntu Utopic) Importance: Undecided Status: New ** Also affec

[Bug 1312991] [NEW] CVE-2014-2851

2014-04-25 Thread John Johansen
*** This bug is a security vulnerability *** Public security bug reported: Integer overflow in the ping_init_sock function in net/ipv4/ping.c in the Linux kernel through 3.14.1 allows local users to cause a denial of service (use-after-free and system crash) or possibly gain privileges via a craf

[Bug 1312993] [NEW] CVE-2014-2851

2014-04-25 Thread John Johansen
*** This bug is a security vulnerability *** Public security bug reported: Integer overflow in the ping_init_sock function in net/ipv4/ping.c in the Linux kernel through 3.14.1 allows local users to cause a denial of service (use-after-free and system crash) or possibly gain privileges via a craf

[Bug 1312993] Re: CVE-2014-2851

2014-04-25 Thread John Johansen
CVE-2014-2851 ** Also affects: linux (Ubuntu Utopic) Importance: Undecided Status: New ** Also affects: linux-fsl-imx51 (Ubuntu Utopic) Importance: Undecided Status: New ** Also affects: linux-mvl-dove (Ubuntu Utopic) Importance: Undecided Status: New ** Also affec

[Bug 1312994] [NEW] CVE-2014-2851

2014-04-25 Thread John Johansen
*** This bug is a security vulnerability *** Public security bug reported: Integer overflow in the ping_init_sock function in net/ipv4/ping.c in the Linux kernel through 3.14.1 allows local users to cause a denial of service (use-after-free and system crash) or possibly gain privileges via a craf

[Bug 1312994] Re: CVE-2014-2851

2014-04-25 Thread John Johansen
CVE-2014-2851 ** Also affects: linux (Ubuntu Utopic) Importance: Undecided Status: New ** Also affects: linux-fsl-imx51 (Ubuntu Utopic) Importance: Undecided Status: New ** Also affects: linux-mvl-dove (Ubuntu Utopic) Importance: Undecided Status: New ** Also affec

[Bug 1308761] [NEW] apparmor spams log with warning message

2014-04-16 Thread John Johansen
ded Assignee: John Johansen (jjohansen) Status: Confirmed ** Affects: linux (Ubuntu Trusty) Importance: Undecided Assignee: John Johansen (jjohansen) Status: Confirmed ** Changed in: linux (Ubuntu) Status: New => Confirmed ** Changed in: linux (

[Bug 1308764] [NEW] apparmor refcount bug in apparmor_kill

2014-04-16 Thread John Johansen
the profile has been replaced but before the task cred has been updated to the new profile. This bug has not been seen in the wild and was found as part of a code audit. ** Affects: linux (Ubuntu) Importance: Undecided Assignee: John Johansen (jjohansen) Status: Confirmed

[Bug 1308765] [NEW] refcount bug in apparmor pivotroot handling

2014-04-16 Thread John Johansen
the code ** Affects: linux (Ubuntu) Importance: Undecided Assignee: John Johansen (jjohansen) Status: Confirmed ** Affects: linux (Ubuntu Trusty) Importance: Undecided Assignee: John Johansen (jjohansen) Status: Confirmed ** Changed in: linux (Ubuntu

[Bug 1300455] Re: linux: 3.2.0-61.92 -proposed tracker

2014-04-17 Thread John Johansen
No CVEs ** Changed in: kernel-sru-workflow/security-signoff Status: In Progress => Invalid -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1300455 Title: linux: 3.2.0-61.92 -proposed tracker

[Bug 1300852] Re: linux: 2.6.32-58.120 -proposed tracker

2014-04-17 Thread John Johansen
Looks good ** Changed in: kernel-sru-workflow/security-signoff Status: In Progress => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1300852 Title: linux: 2.6.32-58.120 -proposed

[Bug 1300867] Re: linux-ti-omap4: 3.2.0-1445.64 -proposed tracker

2014-04-17 Thread John Johansen
No CVEs ** Changed in: kernel-sru-workflow/security-signoff Status: In Progress => Invalid -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1300867 Title: linux-ti-omap4: 3.2.0-1445.64 -propose

[Bug 1300894] Re: linux: 3.5.0-49.73 -proposed tracker

2014-04-17 Thread John Johansen
Looks good ** Changed in: kernel-sru-workflow/security-signoff Status: In Progress => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1300894 Title: linux: 3.5.0-49.73 -proposed t

[Bug 1300928] Re: linux: 3.11.0-20.34 -proposed tracker

2014-04-17 Thread John Johansen
Looks good ** Changed in: kernel-sru-workflow/security-signoff Status: In Progress => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1300928 Title: linux: 3.11.0-20.34 -proposed

[Bug 1300956] Re: linux-lts-raring: 3.8.0-39.57~precise1 -proposed tracker

2014-04-17 Thread John Johansen
Looks good ** Changed in: kernel-sru-workflow/security-signoff Status: In Progress => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1300956 Title: linux-lts-raring: 3.8.0-39.57

[Bug 1301073] Re: linux-ti-omap4: 3.5.0-241.57 -proposed tracker

2014-04-17 Thread John Johansen
Looks good ** Changed in: kernel-sru-workflow/security-signoff Status: In Progress => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1301073 Title: linux-ti-omap4: 3.5.0-241.57 -

[Bug 1301071] Re: linux-ec2: 2.6.32-363.76 -proposed tracker

2014-04-17 Thread John Johansen
Looks good ** Changed in: kernel-sru-workflow/security-signoff Status: In Progress => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1301071 Title: linux-ec2: 2.6.32-363.76 -prop

[Bug 1301080] Re: linux-lts-quantal: 3.5.0-49.73~precise1 -proposed tracker

2014-04-17 Thread John Johansen
Looks good ** Changed in: kernel-sru-workflow/security-signoff Status: In Progress => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1301080 Title: linux-lts-quantal: 3.5.0-49.73

[Bug 1301505] Re: linux-lts-saucy: 3.11.0-20.34~precise1 -proposed tracker

2014-04-17 Thread John Johansen
Looks good ** Changed in: kernel-sru-workflow/security-signoff Status: In Progress => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1301505 Title: linux-lts-saucy: 3.11.0-20.34~

[Bug 706999] Re: CVE-2010-3448

2014-04-17 Thread John Johansen
revert ** Changed in: linux-lts-raring (Ubuntu) Status: Won't Fix => New -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/706999 Title: CVE-2010-3448 To manage notifications about this bug go

[Bug 706999] Re: CVE-2010-3448

2014-04-17 Thread John Johansen
revert ** Changed in: linux-lts-raring (Ubuntu Lucid) Status: Won't Fix => Invalid -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/706999 Title: CVE-2010-3448 To manage notifications about th

[Bug 706999] Re: CVE-2010-3448

2014-04-17 Thread John Johansen
revert ** Changed in: linux-lts-raring (Ubuntu Precise) Status: Won't Fix => Invalid -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/706999 Title: CVE-2010-3448 To manage notifications about

[Bug 706999] Re: CVE-2010-3448

2014-04-17 Thread John Johansen
revert ** Changed in: linux-lts-raring (Ubuntu Quantal) Status: Won't Fix => Invalid -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/706999 Title: CVE-2010-3448 To manage notifications about

[Bug 706999] Re: CVE-2010-3448

2014-04-17 Thread John Johansen
revert ** Changed in: linux-lts-raring (Ubuntu Raring) Status: Won't Fix => Invalid -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/706999 Title: CVE-2010-3448 To manage notifications about t

[Bug 1298611] Re: [FFe] apparmor signal and ptrace mediation

2014-03-27 Thread John Johansen
** Description changed: = linux = This feature freeze exception is requested for signal and ptrace mediation via apparmor in the kernel. When used with a compatible apparmor userspace, signals and ptrace rules are supported. When used without a compatible apparmor userspace (eg, on a precis

[Bug 1290512] Re: linux-lts-raring: 3.8.0-38.56~precise1 -proposed tracker

2014-03-29 Thread John Johansen
Looks good ** Changed in: kernel-sru-workflow/security-signoff Status: In Progress => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1290512 Title: linux-lts-raring: 3.8.0-38.56~

[Bug 1290673] Re: linux-ti-omap4: 3.5.0-240.56 -proposed tracker

2014-03-29 Thread John Johansen
No CVEs ** Changed in: kernel-sru-workflow/security-signoff Status: In Progress => Invalid -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1290673 Title: linux-ti-omap4: 3.5.0-240.56 -proposed

[Bug 1290551] Re: linux: 3.11.0-19.33 -proposed tracker

2014-03-29 Thread John Johansen
No CVEs ** Changed in: kernel-sru-workflow/security-signoff Status: In Progress => Invalid -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1290551 Title: linux: 3.11.0-19.33 -proposed tracker

[Bug 1291126] Re: linux-lts-saucy: 3.11.0-19.33~precise1 -proposed tracker

2014-03-29 Thread John Johansen
No CVEs ** Changed in: kernel-sru-workflow/security-signoff Status: In Progress => Invalid -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1291126 Title: linux-lts-saucy: 3.11.0-19.33~precise1

[Bug 1290676] Re: linux-lts-quantal: 3.5.0-48.72~precise1 -proposed tracker

2014-03-29 Thread John Johansen
No CVEs ** Changed in: kernel-sru-workflow/security-signoff Status: In Progress => Invalid -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1290676 Title: linux-lts-quantal: 3.5.0-48.72~precise

[Bug 1290459] Re: linux: 3.5.0-48.72 -proposed tracker

2014-03-29 Thread John Johansen
No CVEs ** Changed in: kernel-sru-workflow/security-signoff Status: In Progress => Invalid -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1290459 Title: linux: 3.5.0-48.72 -proposed tracker

[Bug 1295774] Re: ERROR processing policydb rules for profile lxc-container-default, failed to load

2014-03-30 Thread John Johansen
This is fixed in apparmor-2.8.95~2430 the initialization happens as part of the constructor in mount.c mnt_rule::mnt_rule(struct cond_entry *src_conds, char *device_p, struct cond_entry *dst_conds __unused, char *mnt_point_p, int allow_p): mnt_point(m

[Bug 1298611] Re: [FFe] apparmor signal and ptrace mediation

2014-03-30 Thread John Johansen
** Description changed: Background: kernel and apparmor userspace updates to support signal and ptrace mediation. These packages are listed in one bug because they are related, but the FFes may be granted and the uploads may happen at different times. = linux = Summary: This featu

[Bug 1298611] Re: [FFe] apparmor signal and ptrace mediation

2014-03-31 Thread John Johansen
** Description changed: Background: kernel and apparmor userspace updates to support signal and ptrace mediation. These packages are listed in one bug because they are related, but the FFes may be granted and the uploads may happen at different times. = linux = Summary: This featu

[Bug 1298611] Re: [FFe] apparmor signal and ptrace mediation

2014-03-31 Thread John Johansen
** Description changed: Background: kernel and apparmor userspace updates to support signal and ptrace mediation. These packages are listed in one bug because they are related, but the FFes may be granted and the uploads may happen at different times. = linux = Summary: This featu

[Bug 1319561] [NEW] CVE-2014-3144

2014-05-14 Thread John Johansen
*** This bug is a security vulnerability *** Public security bug reported: The (1) BPF_S_ANC_NLATTR and (2) BPF_S_ANC_NLATTR_NEST extension implementations in the sk_run_filter function in net/core/filter.c in the Linux kernel through 3.14.3 do not check whether a certain length value is sufficie

[Bug 1319561] Re: CVE-2014-3144

2014-05-14 Thread John Johansen
CVE-2014-3144 ** Also affects: linux (Ubuntu Utopic) Importance: Undecided Status: New ** Also affects: linux-fsl-imx51 (Ubuntu Utopic) Importance: Undecided Status: New ** Also affects: linux-mvl-dove (Ubuntu Utopic) Importance: Undecided Status: New ** Also affec

[Bug 1319563] [NEW] CVE-2014-3145

2014-05-14 Thread John Johansen
*** This bug is a security vulnerability *** Public security bug reported: The BPF_S_ANC_NLATTR_NEST extension implementation in the sk_run_filter function in net/core/filter.c in the Linux kernel through 3.14.3 uses the reverse order in a certain subtraction, which allows local users to cause a

[Bug 1319563] Re: CVE-2014-3145

2014-05-14 Thread John Johansen
CVE-2014-3145 ** Also affects: linux (Ubuntu Utopic) Importance: Undecided Status: New ** Also affects: linux-fsl-imx51 (Ubuntu Utopic) Importance: Undecided Status: New ** Also affects: linux-mvl-dove (Ubuntu Utopic) Importance: Undecided Status: New ** Also affec

[Bug 899463] Re: CVE-2011-1162

2014-05-17 Thread John Johansen
** No longer affects: linux-armadaxp (Ubuntu Quantal) ** No longer affects: linux-ec2 (Ubuntu Quantal) ** No longer affects: linux-lts-saucy (Ubuntu Quantal) ** No longer affects: linux-lts-quantal (Ubuntu Quantal) ** No longer affects: linux-mvl-dove (Ubuntu Quantal) ** No longer affects: lin

[Bug 899466] Re: CVE-2011-2203

2014-05-17 Thread John Johansen
** No longer affects: linux-armadaxp (Ubuntu Quantal) ** No longer affects: linux-ec2 (Ubuntu Quantal) ** No longer affects: linux-lts-saucy (Ubuntu Quantal) ** No longer affects: linux-lts-quantal (Ubuntu Quantal) ** No longer affects: linux-mvl-dove (Ubuntu Quantal) ** No longer affects: lin

[Bug 927885] Re: CVE-2011-2393

2014-05-18 Thread John Johansen
** No longer affects: linux-armadaxp (Ubuntu Quantal) ** No longer affects: linux-ec2 (Ubuntu Quantal) ** No longer affects: linux-lts-saucy (Ubuntu Quantal) ** No longer affects: linux-lts-quantal (Ubuntu Quantal) ** No longer affects: linux-mvl-dove (Ubuntu Quantal) ** No longer affects: lin

[Bug 869237] Re: CVE-2011-2491

2014-05-18 Thread John Johansen
** No longer affects: linux-armadaxp (Ubuntu Quantal) ** No longer affects: linux-ec2 (Ubuntu Quantal) ** No longer affects: linux-lts-saucy (Ubuntu Quantal) ** No longer affects: linux-lts-quantal (Ubuntu Quantal) ** No longer affects: linux-mvl-dove (Ubuntu Quantal) ** No longer affects: lin

[Bug 869245] Re: CVE-2011-2517

2014-05-18 Thread John Johansen
** No longer affects: linux-armadaxp (Ubuntu Quantal) ** No longer affects: linux-ec2 (Ubuntu Quantal) ** No longer affects: linux-lts-saucy (Ubuntu Quantal) ** No longer affects: linux-lts-quantal (Ubuntu Quantal) ** No longer affects: linux-mvl-dove (Ubuntu Quantal) ** No longer affects: lin

[Bug 869243] Re: CVE-2011-2496

2014-05-18 Thread John Johansen
** No longer affects: linux-armadaxp (Ubuntu Quantal) ** No longer affects: linux-ec2 (Ubuntu Quantal) ** No longer affects: linux-lts-saucy (Ubuntu Quantal) ** No longer affects: linux-lts-quantal (Ubuntu Quantal) ** No longer affects: linux-mvl-dove (Ubuntu Quantal) ** No longer affects: lin

[Bug 869250] Re: CVE-2011-2525

2014-05-18 Thread John Johansen
** No longer affects: linux-armadaxp (Ubuntu Quantal) ** No longer affects: linux-ec2 (Ubuntu Quantal) ** No longer affects: linux-lts-saucy (Ubuntu Quantal) ** No longer affects: linux-lts-quantal (Ubuntu Quantal) ** No longer affects: linux-mvl-dove (Ubuntu Quantal) ** No longer affects: lin

[Bug 880890] Re: CVE-2011-3209

2014-05-18 Thread John Johansen
** No longer affects: linux-armadaxp (Ubuntu Quantal) ** No longer affects: linux-ec2 (Ubuntu Quantal) ** No longer affects: linux-lts-saucy (Ubuntu Quantal) ** No longer affects: linux-lts-quantal (Ubuntu Quantal) ** No longer affects: linux-mvl-dove (Ubuntu Quantal) ** No longer affects: lin

[Bug 880893] Re: CVE-2011-3347

2014-05-18 Thread John Johansen
** No longer affects: linux-armadaxp (Ubuntu Quantal) ** No longer affects: linux-ec2 (Ubuntu Quantal) ** No longer affects: linux-lts-saucy (Ubuntu Quantal) ** No longer affects: linux-lts-quantal (Ubuntu Quantal) ** No longer affects: linux-mvl-dove (Ubuntu Quantal) ** No longer affects: lin

[Bug 887291] Re: CVE-2011-3638

2014-05-18 Thread John Johansen
** No longer affects: linux-armadaxp (Ubuntu Quantal) ** No longer affects: linux-ec2 (Ubuntu Quantal) ** No longer affects: linux-lts-saucy (Ubuntu Quantal) ** No longer affects: linux-lts-quantal (Ubuntu Quantal) ** No longer affects: linux-mvl-dove (Ubuntu Quantal) ** No longer affects: lin

[Bug 887298] Re: CVE-2011-4077

2014-05-19 Thread John Johansen
** No longer affects: linux-armadaxp (Ubuntu Quantal) ** No longer affects: linux-ec2 (Ubuntu Quantal) ** No longer affects: linux-lts-saucy (Ubuntu Quantal) ** No longer affects: linux-lts-quantal (Ubuntu Quantal) ** No longer affects: linux-mvl-dove (Ubuntu Quantal) ** No longer affects: lin

[Bug 887299] Re: CVE-2011-4081

2014-05-19 Thread John Johansen
** No longer affects: linux-armadaxp (Ubuntu Quantal) ** No longer affects: linux-ec2 (Ubuntu Quantal) ** No longer affects: linux-lts-saucy (Ubuntu Quantal) ** No longer affects: linux-lts-quantal (Ubuntu Quantal) ** No longer affects: linux-mvl-dove (Ubuntu Quantal) ** No longer affects: lin

[Bug 894369] Re: CVE-2011-4110

2014-05-19 Thread John Johansen
** No longer affects: linux-armadaxp (Ubuntu Quantal) ** No longer affects: linux-ec2 (Ubuntu Quantal) ** No longer affects: linux-lts-saucy (Ubuntu Quantal) ** No longer affects: linux-lts-quantal (Ubuntu Quantal) ** No longer affects: linux-mvl-dove (Ubuntu Quantal) ** No longer affects: lin

[Bug 911397] Re: CVE-2011-4127

2014-05-19 Thread John Johansen
** No longer affects: linux-armadaxp (Ubuntu Quantal) ** No longer affects: linux-ec2 (Ubuntu Quantal) ** No longer affects: linux-lts-saucy (Ubuntu Quantal) ** No longer affects: linux-lts-quantal (Ubuntu Quantal) ** No longer affects: linux-mvl-dove (Ubuntu Quantal) ** No longer affects: lin

[Bug 893147] Re: CVE-2011-4131

2014-05-19 Thread John Johansen
** No longer affects: linux-armadaxp (Ubuntu Quantal) ** No longer affects: linux-ec2 (Ubuntu Quantal) ** No longer affects: linux-lts-saucy (Ubuntu Quantal) ** No longer affects: linux-lts-quantal (Ubuntu Quantal) ** No longer affects: linux-mvl-dove (Ubuntu Quantal) ** No longer affects: lin

[Bug 893148] Re: CVE-2011-4132

2014-05-19 Thread John Johansen
** No longer affects: linux-armadaxp (Ubuntu Quantal) ** No longer affects: linux-ec2 (Ubuntu Quantal) ** No longer affects: linux-lts-saucy (Ubuntu Quantal) ** No longer affects: linux-lts-quantal (Ubuntu Quantal) ** No longer affects: linux-mvl-dove (Ubuntu Quantal) ** No longer affects: lin

[Bug 917829] Re: CVE-2011-4324

2014-05-19 Thread John Johansen
** No longer affects: linux-armadaxp (Ubuntu Quantal) ** No longer affects: linux-ec2 (Ubuntu Quantal) ** No longer affects: linux-lts-saucy (Ubuntu Quantal) ** No longer affects: linux-lts-quantal (Ubuntu Quantal) ** No longer affects: linux-mvl-dove (Ubuntu Quantal) ** No longer affects: lin

[Bug 917835] Re: CVE-2011-4325

2014-05-19 Thread John Johansen
** No longer affects: linux-armadaxp (Ubuntu Quantal) ** No longer affects: linux-ec2 (Ubuntu Quantal) ** No longer affects: linux-lts-saucy (Ubuntu Quantal) ** No longer affects: linux-lts-quantal (Ubuntu Quantal) ** No longer affects: linux-mvl-dove (Ubuntu Quantal) ** No longer affects: lin

[Bug 894373] Re: CVE-2011-4326

2014-05-19 Thread John Johansen
** No longer affects: linux-armadaxp (Ubuntu Quantal) ** No longer affects: linux-ec2 (Ubuntu Quantal) ** No longer affects: linux-lts-saucy (Ubuntu Quantal) ** No longer affects: linux-lts-quantal (Ubuntu Quantal) ** No longer affects: linux-mvl-dove (Ubuntu Quantal) ** No longer affects: lin

[Bug 894374] Re: CVE-2011-4330

2014-05-19 Thread John Johansen
** No longer affects: linux-armadaxp (Ubuntu Quantal) ** No longer affects: linux-ec2 (Ubuntu Quantal) ** No longer affects: linux-lts-saucy (Ubuntu Quantal) ** No longer affects: linux-lts-quantal (Ubuntu Quantal) ** No longer affects: linux-mvl-dove (Ubuntu Quantal) ** No longer affects: lin

[Bug 917706] Re: CVE-2012-0038

2014-05-19 Thread John Johansen
** No longer affects: linux-armadaxp (Ubuntu Quantal) ** No longer affects: linux-ec2 (Ubuntu Quantal) ** No longer affects: linux-lts-saucy (Ubuntu Quantal) ** No longer affects: linux-lts-quantal (Ubuntu Quantal) ** No longer affects: linux-mvl-dove (Ubuntu Quantal) ** No longer affects: lin

[Bug 947997] Re: CVE-2012-1090

2014-05-19 Thread John Johansen
** No longer affects: linux-armadaxp (Ubuntu Quantal) ** No longer affects: linux-ec2 (Ubuntu Quantal) ** No longer affects: linux-lts-saucy (Ubuntu Quantal) ** No longer affects: linux-lts-quantal (Ubuntu Quantal) ** No longer affects: linux-mvl-dove (Ubuntu Quantal) ** No longer affects: lin

[Bug 949905] Re: CVE-2012-1097

2014-05-19 Thread John Johansen
** No longer affects: linux-armadaxp (Ubuntu Quantal) ** No longer affects: linux-ec2 (Ubuntu Quantal) ** No longer affects: linux-lts-saucy (Ubuntu Quantal) ** No longer affects: linux-lts-quantal (Ubuntu Quantal) ** No longer affects: linux-mvl-dove (Ubuntu Quantal) ** No longer affects: lin

[Bug 952828] Re: CVE-2012-1146

2014-05-19 Thread John Johansen
** No longer affects: linux-armadaxp (Ubuntu Quantal) ** No longer affects: linux-ec2 (Ubuntu Quantal) ** No longer affects: linux-lts-saucy (Ubuntu Quantal) ** No longer affects: linux-lts-quantal (Ubuntu Quantal) ** No longer affects: linux-mvl-dove (Ubuntu Quantal) ** No longer affects: lin

[Bug 987569] Re: CVE-2012-2121

2014-05-19 Thread John Johansen
** No longer affects: linux-armadaxp (Ubuntu Quantal) ** No longer affects: linux-ec2 (Ubuntu Quantal) ** No longer affects: linux-lts-saucy (Ubuntu Quantal) ** No longer affects: linux-lts-quantal (Ubuntu Quantal) ** No longer affects: linux-mvl-dove (Ubuntu Quantal) ** No longer affects: lin

[Bug 990368] Re: CVE-2012-2133

2014-05-19 Thread John Johansen
** No longer affects: linux-armadaxp (Ubuntu Quantal) ** No longer affects: linux-ec2 (Ubuntu Quantal) ** No longer affects: linux-lts-saucy (Ubuntu Quantal) ** No longer affects: linux-lts-quantal (Ubuntu Quantal) ** No longer affects: linux-mvl-dove (Ubuntu Quantal) ** No longer affects: lin

[Bug 1002505] Re: CVE-2012-2375

2014-05-20 Thread John Johansen
** No longer affects: linux-armadaxp (Ubuntu Quantal) ** No longer affects: linux-ec2 (Ubuntu Quantal) ** No longer affects: linux-lts-saucy (Ubuntu Quantal) ** No longer affects: linux-lts-quantal (Ubuntu Quantal) ** No longer affects: linux-mvl-dove (Ubuntu Quantal) ** No longer affects: lin

[Bug 1091187] Re: CVE-2012-5374

2014-05-20 Thread John Johansen
** No longer affects: linux-armadaxp (Ubuntu Quantal) ** No longer affects: linux-ec2 (Ubuntu Quantal) ** No longer affects: linux-lts-saucy (Ubuntu Quantal) ** No longer affects: linux-lts-quantal (Ubuntu Quantal) ** No longer affects: linux-mvl-dove (Ubuntu Quantal) ** No longer affects: lin

[Bug 1131331] Re: CVE-2012-4542

2014-05-20 Thread John Johansen
** No longer affects: linux-armadaxp (Ubuntu Quantal) ** No longer affects: linux-ec2 (Ubuntu Quantal) ** No longer affects: linux-lts-saucy (Ubuntu Quantal) ** No longer affects: linux-lts-quantal (Ubuntu Quantal) ** No longer affects: linux-mvl-dove (Ubuntu Quantal) ** No longer affects: lin

[Bug 1024497] Re: CVE-2012-3400

2014-05-20 Thread John Johansen
** No longer affects: linux-armadaxp (Ubuntu Quantal) ** No longer affects: linux-ec2 (Ubuntu Quantal) ** No longer affects: linux-lts-saucy (Ubuntu Quantal) ** No longer affects: linux-lts-quantal (Ubuntu Quantal) ** No longer affects: linux-mvl-dove (Ubuntu Quantal) ** No longer affects: lin

[Bug 963685] Re: Please consider backporting killable request_module() patchset

2014-05-20 Thread John Johansen
** No longer affects: linux-armadaxp (Ubuntu Quantal) ** No longer affects: linux-ec2 (Ubuntu Quantal) ** No longer affects: linux-lts-saucy (Ubuntu Quantal) ** No longer affects: linux-lts-quantal (Ubuntu Quantal) ** No longer affects: linux-mvl-dove (Ubuntu Quantal) ** No longer affects: lin

[Bug 1091188] Re: CVE-2012-5375

2014-05-20 Thread John Johansen
** No longer affects: linux-armadaxp (Ubuntu Quantal) ** No longer affects: linux-ec2 (Ubuntu Quantal) ** No longer affects: linux-lts-saucy (Ubuntu Quantal) ** No longer affects: linux-lts-quantal (Ubuntu Quantal) ** No longer affects: linux-mvl-dove (Ubuntu Quantal) ** No longer affects: lin

[Bug 1285041] Re: CVE-2012-6638

2014-05-20 Thread John Johansen
** No longer affects: linux-armadaxp (Ubuntu Quantal) ** No longer affects: linux-ec2 (Ubuntu Quantal) ** No longer affects: linux-lts-saucy (Ubuntu Quantal) ** No longer affects: linux-lts-quantal (Ubuntu Quantal) ** No longer affects: linux-mvl-dove (Ubuntu Quantal) ** No longer affects: lin

[Bug 1153813] Re: CVE-2013-0914

2014-05-20 Thread John Johansen
** No longer affects: linux-armadaxp (Ubuntu Quantal) ** No longer affects: linux-ec2 (Ubuntu Quantal) ** No longer affects: linux-lts-saucy (Ubuntu Quantal) ** No longer affects: linux-lts-quantal (Ubuntu Quantal) ** No longer affects: linux-mvl-dove (Ubuntu Quantal) ** No longer affects: lin

[Bug 1129192] Re: CVE-2013-0871

2014-05-20 Thread John Johansen
** No longer affects: linux-armadaxp (Ubuntu Quantal) ** No longer affects: linux-ec2 (Ubuntu Quantal) ** No longer affects: linux-lts-saucy (Ubuntu Quantal) ** No longer affects: linux-lts-quantal (Ubuntu Quantal) ** No longer affects: linux-mvl-dove (Ubuntu Quantal) ** No longer affects: lin

<    4   5   6   7   8   9   10   11   12   13   >