DELTA 538376 0 32730 SVN&7%fE>x*sAbU/2 x>Z]Qx^Rn08xi:H-7E@`E6Б&OTȓ]{ܡ:H;={GJFJ+8*n}61[QfRͶֻۭ˪=`T}4:#-R(s:5;(3tb%fYP6 *3b}h955C!DnQ^M)CY8EJ~^Z#)v+?Z * 1vaŞP@@1Oh>HЌ) xo9|Yki҆ gDa:mV0!i)_F=#"Zn@BE}v@ql$x^=o0 ܯ njC6b@tl([-|ׇE:$'%!] ~0BKK;Uݱį,+ѺVj_cB 1,X |R"c4"M}rKMλ3YCa3͖Bwػm$׍x<b苓UJafƛWg. M"p`NH& D2[ŘIkBsQ?;~.ߡKhc^/=xŪqr*[y\alVʘV:4Q[ٵi9tMg޿z%X?&67Q^׸A{1P4/̚hM~Wb0vi]~x^n0W,;?L$ TDg8%ةx:*t}t+é \)h€umN_6 k(vRIP f"P#or.6Jj;KZj '+z,V(!/8& ̹#P3'l{T*c;[head access to a cd(4) device to arbitrarily overwrite kernel memory when some media is present in the device.

Impact:

A user in the operator group can make use of this interface to gain root privileges on a system with a cd(4) device when some media is present in the device9-5602 SA-19:11.cd_ioctlff82610f-b309-11e9-a87f-a4badb2f4699"> FreeBSD -- Kernel stack disclosure in UFS/FFS7 11.211.2_1~B?qv@c#]x^Os ɧ`SЈffSO=fH(XEgZ=u2rz[ؘb/!+ZBJ0<*Vr0 kM#Vp0^G:PҰ8]V=WОF(w(',C]>of9w;!:h!U%"YѨӞ:݀-Y׷>c(N=bv@]Sx^uRMo =ws0t݈\#RVì alV. cĐ"zQU#F,^EmF7dh?XP)io 1&)ڏ|ZEΉHkwNaҐ6Qx痥&gvfG^VRܼ<3U-ٺ|Jqnjw9[lhE4\˲LStfaVc,8e'H QuYXVu:یA+'5‚y(,uQv{ɨ2I0ҏ?#0M? {âHsxʜm?v -7YζXNvb/׆x"2ѹ@qfilg`Rrr7y )H3 J{v7]cx^n0 S9ϖ.E\0`O@t,ġ\N=E/;'6_)n6pjbhWgEm^(SP[XI%T rMUeBu ~w}s[>CQBvoq%x qG3XDɬPw8rIHRovsY4#әP1zXLmi,MӃdynո8r0Z3M';!hw7Y6wUpc/lvB睒'vIR[ԎƤ-\4` ߺ!/ Z>gRoJwY+]Tx^PN0=_1/Yh+Y9PqN&Ǥ-X/C.~Z"5gf?nB`:K -ܙ8\; i1zLR\Ir\H m0LccM..f<ڎ\"DfxA.-*KLao{|Asq0ΐ+DCDSvX8tXSKYqחb'V|qȱ9~#Eq-fZ]P}v&'OѠiJ>>48]g="6a177c87-9933-11e7-93f7-d43d7e971a1b"> GitLabgitlab 1.0.09.3.10 9.4.09.4.5 9.5.09.59/07/gitlab-9-dot-5-dot-49/07/gitlab-9-dot-5-dot-4-security-release/ CVE-2017-5029 CVE-2016-4738 2017-09-07 2017-09-14 t]Ux^R=S0ɯФWd4\q7 Z^'Eppv޾NX:Թ3'oͲ5腇&ΊK\+1!U4Zr+v2nNUG.%W*5tU-g-qڱ1쥷u`ƱQ`~0{z s̮#6q0:tJw ҵesRb4lZ_~iCg'[!g텏{ 0FqLXnįO7i66mYo0z\~C[ `ݞLգ2}ׁc?~1))/$\pԼ_9)MYlZ觤B)ܼ,{@s#Y*Q]\x^MO0 +tE*āw!K%,Ŀ'[W1)kQz^s)PZX舊 VT݈42}vP-u=taH0AĕK(rb8d1K%hFF.=v :,sn4CO=hUAq%!:~Gu]NZQ z!9+L?ܟ(xnrtD@ s>kȀQV5 }90u g]AY#9}E}wù:Y R6]xx^Qj0=_1@eNlea(JQVFN_qBO5̌{zj5o߇ۛ#iuH`]c+-&w &GS:F"]O'c_ܯ6i=جaYͧ8v%9e)ȶEz;t IB:XN_1A!`0r8r'i~ɊǼ`U^NdƦ4^B ;y\Ht?]^x^}R0=_1-c˛MQ -Pa{4NԵ%w$ܯYZ͛%Hs?4*bH,/Sm%}=|Kqt'7 sfa >jq+Z!0ͷ(# gBʜ o*Y?j-cwޅ±wաj>(o|ޟ8WH'3RDc'v#\b".8? qt鴘 Y` L$ruْ݀Apg锔٬r~#Brߜz_ 웻% O,r1eL,.cv,sHz>@LJ@M]x^Q]O0}_axce61>w6o7,msNOooqȉ+v.|A#$,N_'Kesl[\}mFJ9Qצ*}L[)n8igO>/N,d`PP-]7TYmkh tPqG:~Uj'I|J~\yJ\x^QMs =7ɩ= (~5tzW\#-J4Dӏc#!؂;v ;* =vHVA8lQ*W3=zxWT[ {BGtk'T9BW%Ē?)yo42X}Lq?֜E`yz=0,0Kx2V!g?\o`+UN]$].x^}r#!Ec+#!-v ֖崇iI*@G2 ݚh_܈aG%Q?hoHЩW\u|*ӉuR)1#nRR`T bZט. t! Б^A$e!)E0hH&CSJ4';tkS.FIJ3oUK7KdejvV런 ?w^rrֶ_TpQ7Z&j`uM6ڎuj#q,?J͌ɳ` ^{(ipP:7Xf4}CہQ _:]Dx^R=o0_AdjI-hNPd (I"**I)Ϳ/)qJp8Q K G6T2X5[o>>?>yKF(DҎ|P؞"+SN2uw̱Xr!74|z[R/ڎ@44,ΌI9a&OUl MK\Kj4 œSMLcUI-Gift+5E4BM={y3(QJY#;WF;E42X%oo?ys=,#E%N_?XʓM2(qf/,|`ׁ >JPvU]cx^n OA^AԊ 5i`p1Uٷ/m6𝟣u-9 1Awևn.!\!\>v>8k]2LCU]%QZk m0*Qk5j'ډc (vVvȊ{{_ܺ|B9^twI&A=K)Ș$M@`!n /{]o`&kۛ6o;p':>M^Go{X|M|1>n\=폰6/#跍SCօO'ʷ?sArxeϷug`ﴲOnLiRW?!eC<x4{pbTB#섌5HZ ~`@!]Cx^ҽ P ^Enx{< Etw`gzx/dl\3ϡ}y;阖Կ}wݗ4U 1e[0V1I[# Ϋ,"`HF&M!אHb^K؆à)<Z0[rR>ASo ˟UEʪ̫8tI6txsXGaŊrBLl cmytKJ!,~)ItL҃DJ7gU t)іE% <(h/B/ɇ|\{vېjv&)X{$''''O ϭ :>M5q[M|LJKx^un SX=m-*e(8-Hּj|?v{ It%5%1aF>M$ .>>lz6|^;3N.%`Hvfq(w5،-8G .guСSݝc (t6&NgއYwl4w!MMT~YC.e-AȪ)r('pӏQ#{QT |CFɪ>jJ~41)*Y`ޘ0)&~ ܮcuJ}v@R]cx^Mn0EW^@$zDR"(.ɑDYM{13w`xJ(cUZ&qFty$_g@%lGiRe5ɷ#/bG>.S8Á)+ gBqm Y`sʶ̳pgi~h.jVxU$[Q3 e+jOՁ{M%iM/uʽiMϓ.9+[Rc2[#Ί$,gUULյAf%>ԞZcSi;pP7$xb9h'!vySk*ev]?1<Fޒq=#Yd=ml'2*dn;!Y*u~^,6'CRsY&$Z79'% dV+we*xwia 9Mܢj'"4y_ց uO.].x^ҽN0qj$THl,Z8v }zRP'7q T@w Pc*ze6M;-//ڨgi|b\p*Vmz!eA9%-XI6[r 8nr X5h} /&bqqGxE u89p)HG鵂2 .3uFFR\_;fW~-5|RL+dW@]x^mP]k }^ݚIF`[&2iڴlL{疼ڕ\{Qr_`UB^6wʶeMzĂ 2ť`lxE\.${8ymtMƠtJ0!4J.NUp#!4m`n& 8`JƔ+C>EɶC*R+YpAy$5nS֠\F+y l/F#pѝ}gMTtqT j$w!Rf`Á wN^]Ux^MRM0=b m[ ]JvH $8ƪcݴF'y>f e3:c㬍? }?.r݊S;3ݽ*EC"x^4P/V؋2MfwGɚɶԧ7*Ez0ɟ&!øLKg#HὪbm{ 0n&~: dq1pYR  EL˧jE&1w7֣Xa~$ݥl ށ0dv醤@a nյ,"~D=OI:M:"lc(IڠȞ@ȧl>,YOU5RW~+t][&PpX5^vbBΠ=dM?L@] x^UMo0 ˯ |%l']3zq%:Vc}LOJӉ"%)Uea/m!^^֣PRÀ:r`zP+F Q',4G0 3K2,ƝlBTSF9F-c[-zOh5L x3N!BGfW< &JFIXD~:3I3r'm( F :8#&N iL$8v>3,KڷZ1`x"ON|9vyuyazrQ#0t(r߰Gqs=W Qd& f)g˺< o0 o<ւvk{&uT^/p:]^R}xƹJ"l r@㇧܊j@dRgLy8(j7wR‚Yۀ,']R `Ѝ2 x|Bя;ln | ]!-S#J=v@A]cx^QO0ǟOq٣ e隘黉~ܠ[l˦`7IwGs't:%4u:(He%'kÉ=:4 )etiݗ-x5'?٩M8,srLm˟;N.q c1ebRJ22O,Y'添:[^Z :ӛ1N|G1q'MWA0po'Qj Ty3>^0O д'SIkP:ecξ వ.wUnFq&௥W=['}!Xh|Cl  t^ ^gF^Bx>0|&ze}`V`qVv?D]mx^RAn0<ۯX.Td[ ܊ZɄeJ丯/iR^bfH2hׂWNlu :6u=XXfK.򉦿ؾ! 1i .`NT jC}bãqO~&ߋp{䦷϶}:TU"C+@"1FY[h5cH%ip:96e!{]e]/3)QfUVv[rp,7\L5#qDY-9Pl *.0uh86js}t})ıR>T\j? ]Hãcm2_Se|$oWlr7?')&L>)e\>0x^}Ao ͯX cX_^Ri{0T\ ~q43c5C Ёv s!` Z`%٤.v#Nx0bYi2jDS2z#8~B#q.'4e̺z$Fv:>iZ% ǩCDLuꢵY$pz94sm~]>t<^2U0׽r*E"a E!y^Vc+A:E`>tG@<;tѽ8=OFB) 1Ӹ/.)q'Ly*[gƊUof7cmSVβm /&nPqy]2x^uMo0 q0u˺0P(Cö3-67}5SDJ$:sA?Ps{SA=.+uڮYy_},Jر=Y rŞF|E,"tY5jΧx[OTE{ı*/ߟ X$hA>;^%G>LA4T +,ӿ(Α.C?vdہ)x}@#[4 %}0H˒l~\ O'j`Zfe֘2=L(Y8܌d^ogϑkDK<7;W8;Rgd0rХ۠\x1m!ny:U>J>Yr? +Hzfu[A>؜)|] x^Rn0 }nYqӬf ]1`֗|@AKT'đ IN}(0=QG9`G1 7ƗB~)H~!  \̥ g774 \ߣx^ŷ?`9)- +9j ЛRcoM1;4fJtbn/*aOc"Gt\t9oJJ:!s'(e6)]*,w%3ĶK%c2Ǹ.j)=}9{>*{]Ι/N?dee%%Uh[՟z"jHߞrny햫 lь=_Kihܫ{Jh-|m{@Wjg7㖊SHDO)1rg+k2m;D luhi￵+h`G@gvzv@rkjx^QMO0 =_4V J+nֲ$i=ǐʉ^g^|U Ȉ^hƁokjN >>+tcoGP^-2G([&2qTJMB̽8Ie}wuONWmݝʾmA |@GY]_zq+kQGQaoXI&(&>}Hf &RuY 奪&yM2~2$[p8ԡʳU|<3iPP{> Bt@ ]!x^QN0=ӯq=8Iʶ g u<%qa/\dyM1 Cn[p[\r(aq]A )EX"j OO`# G\\4'Q_Q|~&`aTڀjp؞.sp4cI.x \]gW,7ֶhj]7*]uۿ{0Tc^$G)ѻVϾX ?6?Ϊ ƳK*0h{ߣ.7uo.3)շxR#>)Q4C8BgI$XyT-cySGj2Q<}j]q@R&7x^eRMo0=_1H$Q*D* U(+H'dc_ؓ]ITDN}Ě.T8j }TAv8B|چcZG2\#zf] 1Gruy6\!M}6N;8.P: G"ovua, ' B YR%#DF2G0ZGu$hD :ɶ,' 8ly{笂ezmllh@u n՚O=w-Խ%s!8Zc)0<-Oq7"ecf@|dMb궼0$7Яa S\"%L5?FwWщQLsVtTXf/C Ylwm>q?u>s]Zx^}QO0ǟ˧8qBSy:4 ʱ/EkGƷQ* RϿ/AyGl}[hC ԈVy&e.=wucMilp$24کa6f}!`|篌T)*8'LЩ{%Q ȹԣ  tje}$Bx26As=r}fl4X6% _\//_77 68(FW&埡 Zl;V>ܵ"%f@b0[#@ тVO^־#(_@8>D]x^mRK0 > kOâ*EZR+nىv Ρ>9Hl_uGymޠǮ.ڼj6} +4vֺ< Aዣ2}dFu#lj 6l 5Lw¯EZH&2Su5<|Q1VL[ɋ,KBH Ms#)I(IQK"W|9iDnV~d[ew'*긤Kn?%2jSiD9O&=eQ*}]U*6Bn9~ۖ.h::]Um.Єkqy¬^`]vF{?\ч!rpeL=DT@:q@]x^uMn )PiA٭Y$U{KqG"3䣣 ~\`0 h-#Ftcm&F ȭ,4Z<0+e(}qql\PcQtRqe|Ic"|oؼ.ZdMKݔ\1q|.\x> _O+`о5mp)ۃRjGH19ӟb)ol8gHRvX)c1\ Z\W}o+}pJW$:g)okO}רӢ*z_;zZ}=hX\4WŒ&L."2!N$^0oJw?]6x^j0 SifcT:ښ98y9M  #_T 'j+[KtyV? ӂ?e}0$D9!>Jc H.-ѶsO):nS1Zf _XA]@VLfН :Wera9idn*8zcrJ ٭j k0cu]=`JiŶVE:m =& [MsqDW#'~ƩϯE@JGح;L[r|g蒋E2~tܸcٙ{8Ov@aF@Q]gx^]O ϛOXƸXWmVV^W qiWVqj4CzK{lMn]sjn[ןYkğ h8 a==;ƻA00Jz "-}9I#(B$ 9g1toDzdDfES FH<`ERB!ȁX $)B KNB#d"w&l"z@>P$hz( i٥r,F=o7 \kQWվزr/+HNB**/!DW^USԉWêr(T01Նӻxi]2WiIavn}-S Sh(55]B?٦-@g"E,xp{.@ӆ8] N$lvȂEGvQ]]Px^}Rk0~n#G[1(l[!%W:'ݴ{AX>8 5wKWY&2S%j+DJY7+r{6@;O~=up{ Ѻs\5bW,WS~`b2xP4 ע}7W2BcMz}|Ɖ%[ B!uHBňE.FE>ѹYJļa5ЁAsLz"!0 gX>g710$<(z߃rI a:#|ɶ-w#0#6V*do(j@;|%}Y!tm3ɇ)4dO ] Y-4ھz0TG3x7'}WЖ{ȿF镂p|v@1]-x^]Rn0 =/_AX3^m1JtE5Ie;+0ÆEzO,νufRI<mɤ8E{4GnF/ uOnEwv]yx^Rn0<_)=Ȕn F@.z+hj%HevPc9rOl\`p f K0ZL0 Hj]u!hjïS2&h)a|@2G$ W!~× V?JN^yԲ,1l#uF 8.x,ruؽ%kE"aH#J7%gSU>Y#o|r.Vk`f5W f<ݕG<آ,[첢hQs[ᓹjqzz+ z4]`\i2J{mB)h^Alc$NaIù[Yzl,[ށ5S2ւŀTN.b=wB]|x^RN0 =zKm-C/HwȒ=)`lR8릏3^Zg*d/k61?Ujwf;h$Q" 9_竤yh% U~liS:e0zd%n[vSjD~W(smWT(6<+ZGWyY%ɐa&PLgADI)ɡ-iGxE9 H-|$?IaEOmW 4ICiYтˠvN;wRs] x^UKs )9Han4Cn}V &=)eo_80MO5m7³3)=.dG)1TQMuơWdwn4 ڂT3CR Q*x8YV\ nB)Z@Zt\ tG& {)\Α |>l~ިz%)쐔t`|b̑,Ro Q[I3΢rRK xo  WSQO~0 Tf_hX.SLw33kfqD n3[>l )†V9J|r˚vPp__f1]ᦦ˷e]0F^'aԖ1 JD7 !p= >"dt2+T@._ȚmV/dftY!i1"~zSm.Ȉ|gD­u]&y&2 eLVW2LVP_~ EJiO)QɌ-/GgBJY݈y Nqu$™3 i3OB- 4_LaI!-lh9SG]ЙmWJ/E ?.̟+kq. |#ހs}Id?[GI'x^EQv <_!E$Xar$¢rSTUWS6rB(iQ;sAKT!"bc?oB8h2t>@^PX&l='X5%Dq"~ 0xrIhyۆvj 8MM֌ў5x5:YAGp:[_NH AtRLˌlYcfݷ,Q.˯/UM9i^QHH* 'ۆu)Kev'+d_AڊRhM]J~b8j IT@UF,$S(}&.72)AÔ#Yk4ܲZ.#I[mb,C}4]`x^r0S!NN(eLaWF7RYr%9%<=۴8oWBfơla#I`7;3'gGI{B#ܒ+$qfa=Z~*,aP)o@뢜w~"E-6аCIk[ HcN'WZX˧mRzrVr 3?ofPxH O3|ԿS?:PtC] 3xNrpOSCU^3* ԢWSeS)r:P:ygK<ˋRsQ.'iLm׭4턕oQP[3IxZ[qBtnXb^p>UXO!qV_F#"AQwu^|mvS]=x^Mώ0 SXs BRhڕzުBbj 4f7LF/v~={ q #X\L2+3&k–I2SENjwb>-uUUcвcz 1%|S @[chU_,݂ZuS@>r@U3x^RM0='bɇIE(*`wJCA{g;F8M GY>_}0 0&Oo˝+U]V^Fg`w*9RX:wf}!F8 f-#*IK5iV0Yifdv_Kͳ\Atb?X]R d4>tq83P=K5d( .{UEymRR.ʐTJ&/21?cZST/avKx^}Pn0<'_a\AҖ{IUXU0v@hTOٝIڍZt&[BTYsjAHA[EgG hQPY"7K=.Kv(jЅs"?:<+r* ء*uQf//!lgM$_[DDBX3gc:؊Mnfzb-dtbv(ƍqiʜ4pn