Openwall GNU/*/Linux - a small security-enhanced Linux distro for servers
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Tue, 10 Jan 2012 13:57:01 -0500
From: Xi Wang <xi.wang@...il.com>
To: oss-security@...ts.openwall.com
Subject: CVE request: kernel: xfs heap overflow

Commit ef14f0c1578dce4b688726eb2603e50b62d6665a introduced an integer
overflow in the ACL handling code, which could further lead to
heap-based buffer overflow via a crafted filesystem.

Upstream commits:
http://git.kernel.org/linus/fa8b18edd752a8b4e9d1ee2cd615b82c93cf8bba
http://git.kernel.org/linus/093019cf1b18dd31b2c3b77acce4e000e2cbc9ce

Both commits are needed to fix the vulnerability.

The vulnerability seems to first appear in 2.6.32-rc1.  3.2 contains
only the first commit.

- xi

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Powered by Openwall GNU/*/Linux - Powered by OpenVZ