diff options
| author | Sona Sarmadi <sona.sarmadi@enea.com> | 2016-11-30 13:17:39 +0100 | 
|---|---|---|
| committer | Otavio Salvador <otavio@ossystems.com.br> | 2016-12-09 09:41:45 -0200 | 
| commit | c81b13fce917cfa8a0bb98da18817dcc14ac6b11 (patch) | |
| tree | 5db1efe28a2fceb589c36756ac5df5d004377f22 /dynamic-layers/qt4-layer | |
| parent | a870befa7789197b0091cc18c9c5196a848a75c7 (diff) | |
| download | meta-freescale-c81b13fce917cfa8a0bb98da18817dcc14ac6b11.tar.gz | |
linux-qoriq: fix CVE-2016-0758
Fixes a flaw in the Linux kernel's ASN.1 DER decoder processed
certain certificate files with tags of indefinite length. A local,
unprivileged user could use a specially crafted X.509 certificate
DER file to crash the system or, potentially, escalate their
privileges on the system.
References:
https://lkml.org/lkml/2016/5/12/270
Upstream patch:
https://git.kernel.org/cgit/linux/kernel/git/stable/linux-stable.git/patch/
?id=af00ae6ef5a2c73f21ba215c476570b7772a14fb [backported from stable 3.16]
Signed-off-by: Sona Sarmadi <sona.sarmadi@enea.com>
Signed-off-by: Otavio Salvador <otavio@ossystems.com.br>
Diffstat (limited to 'dynamic-layers/qt4-layer')
0 files changed, 0 insertions, 0 deletions
