oss-sec mailing list archives

Re: CVE request: linux kernel heap issues


From: Kurt Seifried <kurt () seifried org>
Date: Mon, 24 Jan 2011 20:09:57 -0700

Hello,

I don't think these minor issues I reported to the Linux Kernel have
had CVEs assigned to them:

heap contents leak for CAP_NET_ADMIN via ethtool ioctl
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=b00916b189d13a615ff05c9242201135992fcda3

iowarrior usb device heap overflow
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=3ed780117dbe5acb64280d218f0347f238dafed0


Just a note: both fixed in  Kernel 2.6.37:

[root@server v2.6]# grep 3ed780117dbe5acb64280d218f0347f238dafed0 *
ChangeLog-2.6.37:commit 3ed780117dbe5acb64280d218f0347f238dafed0
[root@server v2.6]# grep 3ed780117dbe5acb64280d218f0347f238dafed0 *
ChangeLog-2.6.37:commit 3ed780117dbe5acb64280d218f0347f238dafed0




Thanks,

-Kees

-- 
Kurt Seifried
kurt () seifried org
skype: 1-703-879-3176


Current thread: