• [^] # Debian : ça, c'est fait

    Posté par (site web personnel) . En réponse à la dépêche Faille locale dans les fonctions pipe_*_open() du noyau Linux. Évalué à 2.

    L'équipe de sécurité Debian vient de publier une nouvelle version du noyau, je crois.

    linux-2.6 (2.6.26-19lenny2) stable-security; urgency=high

    * tc: Fix uninitialized kernel memory leak (CVE-2009-3228)
    * random: make get_random_int() more random (CVE-2009-3238)
    * netlink: fix typo in initialization (CVE-2009-3612)
    * drm/r128: Add test for initialisation to all ioctls that require it
    (CVE-2009-3620)
    * AF_UNIX: Fix deadlock on connecting to shutdown socket (CVE-2009-3621)
    * fs: pipe.c null pointer dereference (CVE-2009-3547)
    * KVM: Prevent overflow in KVM_GET_SUPPORTED_CPUID (CVE-2009-3638)