* CVE-2021-27365
- scsi: iscsi: Verify lengths on passthrough PDUs
- sysfs: Add sysfs_emit and sysfs_emit_at to format sysfs output
- scsi: iscsi: Ensure sysfs attributes are limited to PAGE_SIZE
* CVE-2021-27363 // CVE-2021-27364
- scsi: iscsi: Restrict sessions and handles to admin capabilities
* CVE-2021-27364
- scsi: iscsi: respond to netlink with unicast when appropriate
- Add file_ns_capable() helper function for open-time capability checking
- net: Add variants of capable for use on on sockets
- netlink: Make the sending netlink socket availabe in NETLINK_CB
-- Thadeu Lima de Souza Cascardo <email address hidden> Mon, 05 Apr 2021 14:23:29 -0300
This bug was fixed in the package linux - 3.2.0-150.197
---------------
linux (3.2.0-150.197) precise; urgency=medium
* precise/linux: 3.2.0-150.197 -proposed tracker (LP: #1919172)
* CVE-2021-27365
- scsi: iscsi: Verify lengths on passthrough PDUs
- sysfs: Add sysfs_emit and sysfs_emit_at to format sysfs output
- scsi: iscsi: Ensure sysfs attributes are limited to PAGE_SIZE
* CVE-2021-27363 // CVE-2021-27364
- scsi: iscsi: Restrict sessions and handles to admin capabilities
* CVE-2021-27364
- scsi: iscsi: respond to netlink with unicast when appropriate
- Add file_ns_capable() helper function for open-time capability checking
- net: Add variants of capable for use on on sockets
- netlink: Make the sending netlink socket availabe in NETLINK_CB
-- Thadeu Lima de Souza Cascardo <email address hidden> Mon, 05 Apr 2021 14:23:29 -0300