oss-sec mailing list archives
Re: CVE-2013-0913 Linux kernel i915 integer overflow
From: Xin Li <delphij () delphij net>
Date: Thu, 14 Mar 2013 14:56:50 -0700
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Hi, Alexander, On 03/13/13 09:04, Alexander E. Patrakov wrote:
2013/3/12 Kees Cook <keescook () chromium org>:This flaw could lead to a kernel heap overflow by processes with access to the DRM driver: https://lkml.org/lkml/2013/3/11/501Given that FreeBSD also has some sort of i915kms kernel driver now, is it also vulnerable?
Based on our evaluation this also affects FreeBSD and thus we will fix it similarly. However, since users using DRM generally already have physical local access to the system, we do not intend to release a security advisory for this issue. Cheers, - -- Xin LI FreeBSD Deputy Security Officer -----BEGIN PGP SIGNATURE----- iQEcBAEBCgAGBQJRQkeiAAoJEG80Jeu8UPuzf/8H/2ZZJqHvCyZmy04hjnMwtQGD ooZRc5fGOdWJu77gFCpK8i5EG77dyF0SbuDzSho91uKkLrRQqyMQwr2dz2xiGU4l wIPxt9UcEXe5oP36ZFU7AdAcD6mYnORTBv1kmTUsfv26Cp+99nTM6vTHCB6hBZFO SzDsUAaZ6jdl7iemI/QI7WVgKWj5p+ReBFi/WkEcCRaqkrOEDRFyQMvmTwkvTnn2 Sv6L+x1HwiNk2OYsgdm9mJsx2OsUADs7IznPPNZdd5t1/TYQRJKfDbaMdjuv4QgT VyVUs73w73X4x0Ipyxxcpi1OhrIMYiyOBxnnlqPB5/KAXiivSn4SQu5HOtwqf7o= =3nVh -----END PGP SIGNATURE-----
Current thread:
- CVE-2013-0913 Linux kernel i915 integer overflow Kees Cook (Mar 11)
- Re: CVE-2013-0913 Linux kernel i915 integer overflow Alexander E. Patrakov (Mar 13)
- Re: CVE-2013-0913 Linux kernel i915 integer overflow Xin Li (Mar 14)
- Re: CVE-2013-0913 Linux kernel i915 integer overflow Alexander E. Patrakov (Mar 13)