oss-sec mailing list archives

Re: CVE request: kernel: cifs: cifs_create() NULL pointer dereference


From: Greg KH <greg () kroah com>
Date: Tue, 18 May 2010 08:50:34 -0700

On Mon, Apr 05, 2010 at 04:56:03PM +0800, Eugene Teo wrote:
On 04/05/2010 04:51 PM, Eugene Teo wrote:
Reported by Eugene Teo. While creating a file on a server which supports
Unix extensions such as Samba, if a file being created does not supply
nameidata (i.e. nd is NULL), cifs client can trigger a NULL pointer
dereference when calling cifs_posix_open().

http://comments.gmane.org/gmane.linux.file-systems.cifs/5782
https://bugzilla.redhat.com/579445

The code that introduced this is upstream commit c3b2a0c6. Any
kernel version from v2.6.29-rc6 onwards are affected.

Am I correct in that I do not see a fix for this in the upstream kernel
repository yet?

thanks,

greg k-h


Current thread: