Openwall GNU/*/Linux - a small security-enhanced Linux distro for servers
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Tue, 18 Aug 2009 14:28:44 -0400 (EDT)
From: "Steven M. Christey" <coley@...us.mitre.org>
To: oss-security@...ts.openwall.com
cc: "Steven M. Christey" <coley@...us.mitre.org>
Subject: Re: CVE request: kernel: cfg80211: missing NULL
 pointer checks


Use CVE-2009-2844, to be filled in later.

- Steve


On Mon, 17 Aug 2009, Eugene Teo wrote:

> Jon Oberheide wrote:
> > On Fri, 2009-08-14 at 17:33 -0600, dann frazier wrote:
> [...]
> > Also would be nice to get one for the cfg80211 issue:
> > http://patchwork.kernel.org/patch/41218/
> >
> > Reproducer:
> > http://jon.oberheide.org/files/cfg80211-remote-dos.c
>
> Thanks Jon.
>
> "These pointers can be NULL, the is_mesh() case isn't ever hit in the
> current kernel, but cmp_ies() can be hit under certain conditions."
>
> Upstream commit:
> http://git.kernel.org/linus/cd3468bad96c00b5a512f551674f36776129520e
>
> Thanks, Eugene
>

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Powered by Openwall GNU/*/Linux - Powered by OpenVZ