oss-sec mailing list archives

Re: signed integer overflow in common_timer_get on linux 4.15.0-rc1


From: Greg KH <greg () kroah com>
Date: Thu, 7 Dec 2017 12:17:18 +0100

On Thu, Dec 07, 2017 at 06:01:43PM +0800, at zhou wrote:
Hi all,

credit   to   L5@360vulcan team

I fuzzed the linux kernel and find signed integer overflow on linux
4.15.0-rc1+.
the crash log can see below, the .config and the poc file ,please see the
attachments.

Odd, doesn't seem to affect a 4.9 or 4.15-rc2 kernel here on my
machines, is there something specific in the .config that might be
triggering this?

thanks,

greg k-h


Current thread: