oss-sec mailing list archives

Re: CVE Request: more tight ioctl permissions in dl2k driver


From: Marcus Meissner <meissner () suse de>
Date: Mon, 7 May 2012 11:15:58 +0200

On Sat, May 05, 2012 at 12:03:28AM +0200, Florian Weimer wrote:
* Marcus Meissner:

Stephan Mueller reported lack of capable(CAP_NET_ADMIN) checks
in private ioctls in the dl2k network card driver.

Have you tested the driver with actual hardware under load?
The last time I tested it, it was not really usable.

No, this was a source level audit only.

Ciao, Marcus


Current thread: