oss-sec mailing list archives

Re: CVE request: kernel: fs/partitions: Kernel heap overflow via corrupted LDM partition tables


From: Josh Bressers <bressers () redhat com>
Date: Wed, 23 Feb 2011 14:59:59 -0500 (EST)

----- Original Message -----

The kernel automatically evaluates partition tables of storage devices.
The code for evaluating LDM partitions (in fs/partitions/ldm.c) contains
a bug that allows to overflow the kernel heap. It may be possible to
escalate privileges by exploiting this bug.

(This bug is distinct from the LDM bug reported by Eugene Teo on
2011-02-23.)

This should affect both, 2.4 and 2.6 kernel. As a prerequisite,
CONFIG_LDM_PARTITION needs to be set.


Can you point to a commit message or something else that is public? It's
not clear how this differs from Eugene's request.

Thanks.

-- 
    JB


Current thread: