On Thu, Sep 30, 2021 at 3:33 PM Nobuhiro Iwamatsu
-----Original Message-----This commit can be applied directly to 4.14 and 4.19.
From: cip-dev@... [mailto:cip-dev@...] On Behalf Of Masami Ichikawa
Sent: Thursday, September 30, 2021 9:12 AM
To: cip-dev <cip-dev@...>
Subject: [cip-dev] New CVE entry this week
It's this week's CVE report.
This week reported one new CVE.
* New CVEs
CVE-2021-20317: lib/timerqueue: Rely on rbtree semantics for next timer
This bug has been fixed in 5.4-rc1 so that before 5.4 kernels are
affected. For 4.19, patch can be applied without any modification. For
4.4, it needs to modify patch to apply it.
According to the description in
it describes "This flaw allows a local attacker with special user
privileges to cause a denial of service" so I think this vulnerability
severity may be low.
CVSS v3 score is not provided.
However, other LTSs need to be other commit or fixes.
I attached a patch for 4.14 and 4.19.
Thank you for the patch!
It looks good to me.
Cybertrust Japan Co., Ltd.