Cip-kernel-sec Updates for Week of 2021-05-05


Chen-Yu Tsai (Moxa) <wens@...>
 

Hi everyone,

Two new CVEs this week:

- CVE-2021-31829 [bpf: stack pointer protection from speculative
arithmetic] - fixed
Fixes just landed in mainline as part of the merge window. Fixes not
tagged for stable.

- CVE-2021-31916 [md: dm_ioctl: out-of-bounds array access] - fixed
Likely needs backport to 4.9 and earlier.

Additionally, one old CVE is now fixed:

- CVE-2020-26541


Regards
ChenYu

Join cip-dev@lists.cip-project.org to automatically receive all group messages.