Re: CVE-2016-7117 Remote code execution vulnerability in kernel networking subsystem

2016-10-05 Thread Salvatore Bonaccorso
Hi Jan, On Wed, Oct 05, 2016 at 09:49:28AM +0200, Jan Lühr wrote: > Hello, > > > Am 10/05/2016 um 06:52 AM schrieb Salvatore Bonaccorso: > > On Tue, Oct 04, 2016 at 11:54:12PM +0200, Jan Lühr wrote: > >> Hello, > >> Am 10/04/2016 um 07:57 PM schrieb Nicholas Luedtke: > >>> On 10/04/2016 11:40 AM

Re: CVE-2016-7117 Remote code execution vulnerability in kernel networking subsystem

2016-10-05 Thread Jan Lühr
Hello, Am 10/05/2016 um 06:52 AM schrieb Salvatore Bonaccorso: > On Tue, Oct 04, 2016 at 11:54:12PM +0200, Jan Lühr wrote: >> Hello, >> Am 10/04/2016 um 07:57 PM schrieb Nicholas Luedtke: >>> On 10/04/2016 11:40 AM, Felix Knecht wrote: >>> On 10/04/2016 06:38 PM, Jan Lühr wrote: > CVE-20

Re: CVE-2016-7117 Remote code execution vulnerability in kernel networking subsystem

2016-10-04 Thread Salvatore Bonaccorso
Hi, On Tue, Oct 04, 2016 at 11:54:12PM +0200, Jan Lühr wrote: > Hello, > Am 10/04/2016 um 07:57 PM schrieb Nicholas Luedtke: > > On 10/04/2016 11:40 AM, Felix Knecht wrote: > > > >> On 10/04/2016 06:38 PM, Jan Lühr wrote: > >>> CVE-2016-7117 was patched in Android today.I don't see much informati

Re: CVE-2016-7117 Remote code execution vulnerability in kernel networking subsystem

2016-10-04 Thread Jan Lühr
Hello, Am 10/04/2016 um 07:57 PM schrieb Nicholas Luedtke: > On 10/04/2016 11:40 AM, Felix Knecht wrote: > >> On 10/04/2016 06:38 PM, Jan Lühr wrote: >>> CVE-2016-7117 was patched in Android today.I don't see much information >>> right now. The title is rather frightening - the issue appears to be

Re: CVE-2016-7117 Remote code execution vulnerability in kernel networking subsystem

2016-10-04 Thread Nicholas Luedtke
On 10/04/2016 11:40 AM, Felix Knecht wrote: > On 10/04/2016 06:38 PM, Jan Lühr wrote: >> CVE-2016-7117 was patched in Android today.I don't see much information >> right now. The title is rather frightening - the issue appears to be urgent. > The following upstream kernel commit is referenced in t

Re: CVE-2016-7117 Remote code execution vulnerability in kernel networking subsystem

2016-10-04 Thread Felix Knecht
On 10/04/2016 06:38 PM, Jan Lühr wrote: > CVE-2016-7117 was patched in Android today.I don't see much information > right now. The title is rather frightening - the issue appears to be urgent. The following upstream kernel commit is referenced in the security bulletin: https://git.kernel.org/cgit

CVE-2016-7117 Remote code execution vulnerability in kernel networking subsystem

2016-10-04 Thread Jan Lühr
Hello, CVE-2016-7117 was patched in Android today.I don't see much information right now. The title is rather frightening - the issue appears to be urgent. Can you confirm, that common Debian installation are unaffected and cannot be taken over via CVE-2016-7117? If not, I'd like to shut down a f