Re: [PATCH 4.14] scsi:be2iscsi: Fix a kernel address leakage in be_main.c

From: Greg KH
Date: Tue Apr 16 2019 - 04:57:06 EST


On Tue, Apr 16, 2019 at 03:06:34PM +0800, Fuqian Huang wrote:
> Outputting kernel addresses will reveal the locations of kernel code
> and data. And there is no need to print the address of a global object
> beiscsi_iscsi_transport in beiscsi_module_init.
> This case is similar to CVE-2018-7273[1].
> Just remove the print statement.
>
> [1] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-7273
>
> Signed-off-by: Fuqian Huang <huangfq.daxian@xxxxxxxxx>

<formletter>

This is not the correct way to submit patches for inclusion in the
stable kernel tree. Please read:
https://www.kernel.org/doc/html/latest/process/stable-kernel-rules.html
for how to do this properly.

</formletter>