oss-sec mailing list archives
CVE-2016-5400 - linux kernel: denial of service in airspy USB driver.
From: Wade Mealing <wmealing () redhat com>
Date: Mon, 25 Jul 2016 10:50:30 +1000
Hello All, A flaw was found in the linux kernel's implementation of the airspy USB device driver in which a leak was found when a subdev or SDR are plugged into the host. An attacker can create an targeted USB device which can emulate 64 of these devices. Then by emulating an additional device which continuously connects and disconnects, each connection attempt will leak memory which can not be recovered. This issue was assigned CVE-2016-5400. Wade Mealing Red Hat Product Security Team
Current thread:
- CVE-2016-5400 - linux kernel: denial of service in airspy USB driver. Wade Mealing (Jul 24)
- Re: CVE-2016-5400 - linux kernel: denial of service in airspy USB driver. Wade Mealing (Jul 24)
- Re: Re: CVE-2016-5400 - linux kernel: denial of service in airspy USB driver. Greg KH (Jul 24)
- Re: Re: CVE-2016-5400 - linux kernel: denial of service in airspy USB driver. Wade Mealing (Jul 24)
- Re: Re: CVE-2016-5400 - linux kernel: denial of service in airspy USB driver. Luis Henriques (Jul 27)
- Re: Re: CVE-2016-5400 - linux kernel: denial of service in airspy USB driver. Greg KH (Jul 24)
- Re: CVE-2016-5400 - linux kernel: denial of service in airspy USB driver. Wade Mealing (Jul 24)