Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1756946AbdIHTK0 (ORCPT ); Fri, 8 Sep 2017 15:10:26 -0400 Received: from mail.linuxfoundation.org ([140.211.169.12]:58344 "EHLO mail.linuxfoundation.org" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1756834AbdIHTKY (ORCPT ); Fri, 8 Sep 2017 15:10:24 -0400 Date: Fri, 8 Sep 2017 21:10:03 +0200 From: Greg KH To: Takashi Iwai Cc: grygorii tertychnyi , xe-linux-external@cisco.com, linux-kernel@vger.kernel.org, alsa-devel@alsa-project.org Subject: Re: [PATCH] ALSA: msnd: Optimize / harden DSP and MIDI loops Message-ID: <20170908191003.GA19292@kroah.com> References: <20170908160626.24771-1-gtertych@cisco.com> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: User-Agent: Mutt/1.9.0 (2017-09-02) Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Content-Length: 604 Lines: 16 On Fri, Sep 08, 2017 at 06:57:57PM +0200, Takashi Iwai wrote: > On Fri, 08 Sep 2017 18:06:25 +0200, > grygorii tertychnyi wrote: > > > > Hi Greg, > > > > Could you please apply it for 4.4-stable. > > This fixes https://nvd.nist.gov/vuln/detail/CVE-2017-9985 > > This vulnerability is just non-issue. You can't get it working > practically; it requires a modified hardware of the decade old ISA > sound card, and yet the system has to load / set up the module > beforehand. We should withdraw it from CVE, IMO. Hah, good luck trying to get a CVE withdrawn, people seem to love the foolish things...