oss-sec mailing list archives

Re: kernel: [PARISC] led.c - fix potential stack overflow in led_proc_write()


From: Josh Bressers <bressers () redhat com>
Date: Tue, 3 Aug 2010 16:00:35 -0400 (EDT)

Steve,

This one will need a 2007 ID.

Thanks.

-- 
    JB


----- "Moritz Muehlenhoff" <jmm () inutil org> wrote:

On Tue, Aug 03, 2010 at 11:46:58AM +0800, Eugene Teo wrote:
Ilja reported way back in Nov 2007. A writer to /proc/pdc/led(?)
can
cause the kernel to consume an unbounded amount of stack, and
result
in stack corruption.

http://www.spinics.net/lists/linux-parisc/msg02960.html

If you need a CVE name, change the subject to indicate that. We are
not requesting one as we do not support the PA-RISC architecture in
our distribution.

Debian supports hppa. 

Steven, please assign a CVE ID.

Cheers,
        Moritz


Current thread: