Candidate: CVE-2005-2801 References: URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2801 MLIST:[Acl-Devel] 20050205 [FIX] Long-standing xattr sharing bug URL:http://acl.bestbits.at/pipermail/acl-devel/2005-February/001848.html MLIST:[debian-kernel] 20050809 Re: ACL patches in Debian 2.4 series kernel. URL:http://lists.debian.org/debian-kernel/2005/08/msg00238.html SUSE:SUSE-SA:2005:018 URL:http://www.novell.com/linux/security/advisories/2005_18_kernel.html Description: xattr.c in the ext2 and ext3 file system code for Linux kernel 2.6 does not properly compare the name_index fields when sharing xattr blocks, which could prevent default ACLs from being applied. Bugs: 332381 upstream: released (2.6.11) 2.6.8-sarge-security: released (2.6.8-16sarge1) [fs_ext2_ext3_xattr-sharing.dpatch] 2.4.27-sarge-security: released (2.4.27-10sarge1) [178_fs_ext2_ext3_xattr-sharing.diff] 2.4.27-sid: released (2.4.27-12) [178_fs_ext2_ext3_xattr-sharing.diff] linux-2.6: N/A 2.4.19-woody-security: 2.4.18-woody-security: 2.4.17-woody-security: 2.4.16-woody-security: 2.4.17-woody-security-hppa: 2.4.17-woody-security-ia64: 2.4.18-woody-security-hppa: