oss-sec mailing list archives

CVE-Request -- Linux ASLR integer overflow


From: Hector Marco <hecmargi () upv es>
Date: Fri, 13 Feb 2015 13:26:12 +0100

Hi,

A bug in Linux ASLR implementation for versions prior to 3.19-rc3 has been found. The issue is that the stack for processes is not properly randomized on some 64 bit architectures due to an integer overflow.

Affected systems have reduced the stack entropy of the processes by four.


Details at:
http://hmarco.org/bugs/linux-ASLR-integer-overflow.html



Could you please assign a CVE-ID for this?



Hector Marco.
http://hmarco.org

Cyber-security researcher at
http://cybersecurity.upv.es/


Current thread: