You cannot select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
openwrt/target/linux
Jo-Philipp Wich f4a4f324cb kernel: update kernel 4.4 to 4.4.71
Fixes the following security vulnerabilities:

CVE-2017-8890
The inet_csk_clone_lock function in net/ipv4/inet_connection_sock.c in the
Linux kernel through 4.10.15 allows attackers to cause a denial of service
(double free) or possibly have unspecified other impact by leveraging use
of the accept system call.

CVE-2017-9074
The IPv6 fragmentation implementation in the Linux kernel through 4.11.1
does not consider that the nexthdr field may be associated with an invalid
option, which allows local users to cause a denial of service (out-of-bounds
read and BUG) or possibly have unspecified other impact via crafted socket
and send system calls.

CVE-2017-9075
The sctp_v6_create_accept_sk function in net/sctp/ipv6.c in the Linux kernel
through 4.11.1 mishandles inheritance, which allows local users to cause a
denial of service or possibly have unspecified other impact via crafted
system calls, a related issue to CVE-2017-8890.

CVE-2017-9076
The dccp_v6_request_recv_sock function in net/dccp/ipv6.c in the Linux
kernel through 4.11.1 mishandles inheritance, which allows local users to
cause a denial of service or possibly have unspecified other impact via
crafted system calls, a related issue to CVE-2017-8890.

CVE-2017-9077
The tcp_v6_syn_recv_sock function in net/ipv6/tcp_ipv6.c in the Linux kernel
through 4.11.1 mishandles inheritance, which allows local users to cause a
denial of service or possibly have unspecified other impact via crafted
system calls, a related issue to CVE-2017-8890.

CVE-2017-9242
The __ip6_append_data function in net/ipv6/ip6_output.c in the Linux kernel
through 4.11.3 is too late in checking whether an overwrite of an skb data
structure may occur, which allows local users to cause a denial of service
(system crash) via crafted system calls.

Ref: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8890
Ref: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9074
Ref: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9075
Ref: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9076
Ref: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9077
Ref: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9242
Ref: https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.71

Signed-off-by: Jo-Philipp Wich <jo@mein.io>
7 years ago
..
adm5120 adm5120: mark the rb1xx subtarget as broken 8 years ago
adm8668 build: fix subtarget descriptions 8 years ago
apm821xx kernel: disable CONFIG_SG_POOL by default 7 years ago
ar7 ar7: diag.sh: use common status_led_* functions 7 years ago
ar71xx kernel: update kernel 4.4 to 4.4.71 7 years ago
arc770 kernel: disable CONFIG_SG_POOL by default 7 years ago
archs38 kernel: disable CONFIG_SG_POOL by default 7 years ago
armvirt armvirt: 64: enable usb support 7 years ago
at91 kernel: remove ubifs xz decompression support 8 years ago
ath25 ath25: add missed HAVE_IRQ_EXIT_ON_IRQ_STACK 7 years ago
au1000 kernel: update kernel 3.18 to version 3.18.43 8 years ago
bcm53xx kernel: disable CONFIG_SG_POOL by default 7 years ago
brcm47xx brcm47xx: remove target specific network preinit config 7 years ago
brcm63xx brcm63xx: drop support for specifying SPI flash part parsers 7 years ago
brcm2708 kernel: disable CONFIG_SG_POOL by default 7 years ago
cns3xxx kernel: disable CONFIG_SG_POOL by default 7 years ago
gemini gemini: rename config-default to config-4.4 8 years ago
generic kernel: update kernel 4.4 to 4.4.71 7 years ago
imx6 kernel: disable CONFIG_SG_POOL by default 7 years ago
ipq806x kernel: disable CONFIG_SG_POOL by default 7 years ago
ixp4xx kernel: update kernel 4.4 to 4.4.53 7 years ago
kirkwood kirkwood: set sata/usb led trigger for NSA3xx 7 years ago
lantiq kernel: disable CONFIG_SG_POOL by default 7 years ago
layerscape kernel: update kernel 4.4 to 4.4.52 7 years ago
malta malta: restore "be" subtarget from being source-only 7 years ago
mcs814x kernel: remove kmod packages for bridge, stp, llc and 8021q 7 years ago
mediatek kernel: disable CONFIG_SG_POOL by default 7 years ago
mpc85xx kernel: disable CONFIG_SG_POOL by default 7 years ago
mvebu kernel: update kernel 4.4 to 4.4.71 7 years ago
mxs mxs: enable nvmem support 7 years ago
octeon kernel: disable CONFIG_SG_POOL by default 7 years ago
omap omap: rework image generation and profiles 7 years ago
omap24xx kernel: clean up usb gadget support 8 years ago
orion kernel: split up 980-arm_openwrt_machtypes.patch and move to target folders 8 years ago
oxnas kernel: update kernel 4.4 to version 4.4.69 7 years ago
pistachio kernel: disable CONFIG_SG_POOL by default 7 years ago
ppc40x build: fix subtarget descriptions 8 years ago
ppc44x ppc44x: mark as broken 8 years ago
ramips kernel: disable CONFIG_SG_POOL by default 7 years ago
rb532 rb532: enable high-res timers, refresh kernel config 7 years ago
sunxi sunxi: sysupgrade: sync with x86 7 years ago
uml uml: Fix sample command line 7 years ago
x86 kernel: disable CONFIG_SG_POOL by default 7 years ago
xburst xburst: enable high-res timers, refresh kernel config 7 years ago
zynq kernel: remove out of tree direct-io disable hack 7 years ago
Makefile