oss-sec mailing list archives

CVE request: kernel: validate size of EFI GUID partition entries


From: Eugene Teo <eugene () redhat com>
Date: Mon, 09 May 2011 11:15:48 +0800

The kernel automatically evaluates partition tables of storage devices. The code for evaluating GUID partitions (in fs/partitions/efi.c) contains a bug that can cause a kernel heap overflow on certain corrupted GUID partition tables.

http://git.kernel.org/linus/fa039d5f6b126fbd65eefa05db2f67e44df8f121
http://bugzilla.redhat.com/show_bug.cgi?id=703026

Thanks, Eugene


Current thread: