oss-sec mailing list archives
Re: CVE Request: information leak in wilc1000 module of Linux kernel
From: Greg KH <greg () kroah com>
Date: Wed, 4 May 2016 06:21:52 -0700
On Wed, May 04, 2016 at 09:12:52AM -0400, Kangjie Lu wrote:
Hello, In the milc1000 module (drivers/staging/wilc1000/wilc_wfi_cfgoperations.c), The 6-bytes stack object “mac” is not initialized but leaked via “nla_put”. This bug may result in leaks of sensitive kernel stack data. The patch of this bug has been accepted by Linux kernel maintainer and will be merged in the next kernel release (see the message bellow). Fix info: *http://www.spinics.net/lists/linux-wireless/msg150352.html <http://www.spinics.net/lists/linux-wireless/msg150352.html>* git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/staging.git Could you please assign a CVE to it?
I wouldn't recommend CVEs for drivers in the staging portion of the Linux kernel tree. It's just too easy to find bugs in them, and very few distros actually enable them. Unless you want to prove that CVEs don't really mean much :) thanks, greg k-h
Current thread:
- CVE Request: information leak in wilc1000 module of Linux kernel Kangjie Lu (May 04)
- Re: CVE Request: information leak in wilc1000 module of Linux kernel Greg KH (May 04)