-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.7 Date: Wed, 06 May 2009 16:22:58 -0600 Source: fai-kernels Binary: fai-kernels Architecture: source amd64 Version: 1.17+etch.24etch2 Distribution: oldstable-security Urgency: high Maintainer: Holger Levsen <holger@debian.org> Changed-By: dann frazier <dannf@debian.org> Description: fai-kernels - special kernels for FAI (Fully Automatic Installation) Changes: fai-kernels (1.17+etch.24etch2) oldstable-security; urgency=high . * Rebuild against linux-source-2.6.18_2.6.18.dfsg.1-24etch2: * Fix buffer underflow in the ib700wdt watchdog driver: - bugfix/all/watchdog-ib700wdt-buffer_underflow.patch See CVE-2008-5702 * nfs: Fix fcntl/close race - bugfix/all/nfs-remove-buggy-lock-if-signalled-case.patch See CVE-2008-4307 * sctp: fix memory overflow - bugfix/all/sctp-avoid-memory-overflow.patch See CVE-2009-0065 * Fix sign-extend ABI issue w/ system calls on various 64-bit architectures - bugfix/all/CVE-2009-0029/* See CVE-2009-0029 * security: introduce missing kfree - bugfix/all/security-keyctl-missing-kfree.patch See CVE-2009-0031 * dell_rbu: use scnprintf instead of less secure sprintf - bugfix/all/dell_rbu-use-scnprintf-instead-of-sprintf.patch See CVE-2009-0322 * [hppa] Fix system crash while unwinding a userspace process - bugfix/hppa/userspace-unwind-crash.patch See CVE-2008-5395 * NET: Add preemption point in qdisc_run - bugfix/all/net-add-preempt-point-in-qdisc_run.patch See CVE-2008-5713 * [mips] Fix potential DOS by untrusted user app - bugfix/mips/fix-potential-dos.patch See CVE-2008-5701 * Fix sensitive memory leak in SO_BSDCOMPAT gsopt - bugfix/all/net-SO_BSDCOMPAT-leak.patch - bugfix/all/net-SO_BSDCOMPAT-leak-2.patch See CVE-2009-0676 * skfp: Fix inverted capabilities check logic - bugfix/all/skfp-fix-inverted-cap-logic.patch See CVE-2009-0675 * [amd64] syscall-audit: fix 32/64 syscall hole - bugfix/syscall-audit-fix-32+64-syscall-hole.patch See CVE-2009-0834 * shm: fix shmctl(SHM_INFO) lockup with !CONFIG_SHMEM This issue does not effect pre-build Debian kernels. - bugfix/all/shm-fix-shmctl-SHM_INFO-lockup-without-CONFIG_SHMEM.patch See CVE-2009-0859 * copy_process: fix CLONE_PARENT && parent_exec_id interaction - bugfix/all/copy_process-fix-CLONE_PARENT-and-parent_exec_id-interaction.patch See CVE-2009-0028 * af_rose/x25: Sanity check the maximum user frame size - bugfix/all/af_rose+x25-sanity-check-the-max-user-frame-size.patch See CVE-2009-1265 * NFS: fix an oops in encode_lookup() - bugfix/all/nfs-fix-oops-in-encode_lookup.patch See CVE-2009-1336 * exit_notify: kill the wrong capable(CAP_KILL) check - bugfix/all/exit_notify-kill-wrong-CAP_KILL-check.patch See CVE-2009-1337 * agp: zero pages before sending to userspace - bugfix/all/agp-zero-pages-before-sending-to-userspace.patch See CVE-2009-1192 * cifs: Fix memory overwrite when saving nativeFileSystem field during mount - bugfix/all/cifs-fix-memory-overwrite-when-saving-nativeFileSystem-field-during-mount.patch - bugfix/all/cifs-fix-buffer-size-for-tcon-nativeFileSystem-field.patch - bugfix/all/cifs-remove-unneeded-bcc_ptr-update-in-CIFSTCon.patch See CVE-2009-1439 * Fix mips FTBFS due to a missed rename of the mips-specific sys_pipe symbol. Files: b37bc8f75334963c7f0410c2296e77fb 740 admin extra fai-kernels_1.17+etch.24etch2.dsc 682c3c14e9ef4e7696db50899a02f0b5 59036 admin extra fai-kernels_1.17+etch.24etch2.tar.gz 043c2c51d7aa93e1c4a7fd5b056f0e1d 5962092 admin extra fai-kernels_1.17+etch.24etch2_amd64.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (GNU/Linux) iD8DBQFKAhUthuANDBmkLRkRAterAJ9FHXv1K9BrX1Vpjd6PhFw+SXuUCwCeKPZE NMEHTvhWQqTuFChr1Fvyh+A= =8aoV -----END PGP SIGNATURE----- Accepted: fai-kernels_1.17+etch.24etch2.dsc to pool/main/f/fai-kernels/fai-kernels_1.17+etch.24etch2.dsc fai-kernels_1.17+etch.24etch2.tar.gz to pool/main/f/fai-kernels/fai-kernels_1.17+etch.24etch2.tar.gz fai-kernels_1.17+etch.24etch2_amd64.deb to pool/main/f/fai-kernels/fai-kernels_1.17+etch.24etch2_amd64.deb