oss-sec mailing list archives
CVE request: Linux kernel: USB: io_ti: NULL pointer dereference
From: P J P <ppandit () redhat com>
Date: Wed, 27 Feb 2013 19:39:50 +0530 (IST)
Hello,Linux kernel built with Edgeport USB serial converter driver io_ti, is vulnerable to a NULL pointer dereference flaw. It happens if the device is disconnected while corresponding /dev/ttyUSB? file is in use.
An unprivileged user could use this flaw to crash the system, resulting DoS. Upstream fix: ------------- -> https://git.kernel.org/linus/1ee0a224bc9aad1de496c795f96bc6ba2c394811 Reference: ---------- -> https://bugzilla.redhat.com/show_bug.cgi?id=916191 Thank you. -- Prasad J Pandit / Red Hat Security Response Team DB7A 84C5 D3F9 7CD1 B5EB C939 D048 7860 3655 602B
Current thread:
- CVE request: Linux kernel: USB: io_ti: NULL pointer dereference P J P (Feb 27)
- Re: CVE request: Linux kernel: USB: io_ti: NULL pointer dereference Kurt Seifried (Feb 27)