please upgrade to iscsitarget 1.4.20.2

Bug #618902 reported by Colin Watson
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
linux (Ubuntu)
Fix Released
Medium
Leann Ogasawara

Bug Description

Could you please upgrade to iscsitarget 1.4.20.2? The release notes list the following changes:

- various issues in the iSNS code resulting from buffer boundaries not being
  checked (CVE-2010-2221)
- memory leak in the iSNS ACL code
- the kernel module allocating UAs in atomic context could cause a soft lockup
- handling iSCSI logins was faulty, causing issues with QLogic HBAs
- ietd was not sufficiently protected against multiple instances
- ietd exited when trying to remove targets with active sessions
- MD5/SHA-1 used for CHAP authentication were faulty on big endian platforms

I can deal with the userspace half of it - in fact I'm currently blocked on this to resolve bug 604087.

Revision history for this message
Leann Ogasawara (leannogasawara) wrote :

Hi Colin,

I've pushed a patch to update iscsitarget to 1.4.20.2 and am about to upload a new kernel with this included. Thanks.

Changed in linux (Ubuntu):
assignee: nobody → Leann Ogasawara (leannogasawara)
importance: Undecided → Medium
status: New → Fix Committed
Revision history for this message
Leann Ogasawara (leannogasawara) wrote :

Should be fixed now in linux-2.6.35-16.22:

https://launchpad.net/ubuntu/+source/linux/2.6.35-16.22

linux (2.6.35-16.22) maverick; urgency=low

  [ Andy Whitcroft ]

  * debian -- more agressivly clean up after depmod on purge
    - LP: #618591

  [ Henrik Rydberg ]

  * SAUCE: hid: 3m: Simplify touchsreen emulation logic

  [ Leann Ogasawara ]

  * ubuntu: iscsitarget -- version 1.4.20.2
  * ubuntu: rtl8192se -- update to version 0017.0507.2010
  * rebase to v2.6.35.2
  * [Config] update configs following rebase to v2.6.35.2
  * [Config] update ports configs following rebase to v2.6.35.2

  [ Luke Yelavich ]

  * [Config] Enable new firewire stack on powerpc

  [ Mathieu J. Poirier ]

  * SAUCE: (drop after 2.6.35) ARM: Using gpmc function to init nand flash.
    - LP: #608266\

Changed in linux (Ubuntu):
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.