oss-sec mailing list archives

fix to CVE-2009-4307


From: akuster <akuster () mvista com>
Date: Tue, 03 Apr 2012 12:32:44 -1000

Hello,

Was there a CVE assigned to commit d50f2ab6f050311dbf7b8f5501b25f0bf64a439b?

Commit 503358ae01b70ce6909d19dd01287093f6b6271c ("ext4: avoid divide by
zero when trying to mount a corrupted file system") fixes CVE-2009-4307
by performing a sanity check on s_log_groups_per_flex, since it can be
set to a bogus value by an attacker.

- Armin


Current thread: