oss-sec mailing list archives
CVE request: kernel: remote buffer overflow in bluetooth
From: Dan Rosenberg <dan.j.rosenberg () gmail com>
Date: Fri, 24 Jun 2011 19:15:05 -0400
A remote user can provide a small value for the command size field in the command header of an l2cap configuration request, resulting in an integer underflow when subtracting the size of the configuration request header. This results in copying a very large amount of data via memcpy() and destroying the kernel heap. [1] -Dan [1] http://marc.info/?l=linux-kernel&m=130891911909436&w=2
Current thread:
- CVE request: kernel: remote buffer overflow in bluetooth Dan Rosenberg (Jun 24)
- Re: CVE request: kernel: remote buffer overflow in bluetooth Eugene Teo (Jun 26)