![oss-sec logo](/images/oss-sec-logo.png)
oss-sec mailing list archives
CVE-2009-4138 kernel: firewire: ohci: handle receive packets with a data length of zero
From: Eugene Teo <eugene () redhat com>
Date: Tue, 15 Dec 2009 09:50:31 +0800
Anyone who can open any of the /dev/fw* files on recent version of the new firewire stack can trigger a NULL pointer dereference with ohci 1.0 controllers (or ohci 1.1 controllers that are being used in ohci 1.0 mode because of hardware bugs) by issuing certain ioctls.
On machines with non-blacklisted ohci1.1 controllers, the call does nothing, which is a bug.
https://bugzilla.redhat.com/CVE-2009-4138 http://patchwork.kernel.org/patch/66747/ Thanks, Eugene -- Eugene Teo / Red Hat Security Response Team
Current thread:
- CVE-2009-4138 kernel: firewire: ohci: handle receive packets with a data length of zero Eugene Teo (Dec 14)