Date: Fri, 24 Jul 2009 10:22:53 +0200 From: Marcus Meissner <meissner@...e.de> To: OSS Security List <oss-security@...ts.openwall.com> Subject: md raid null ptr dereference (when sysfs is writable) Hi, http://xorl.wordpress.com/2009/07/21/linux-kernel-md-driver-null-pointer-dereference/ 2.6.30 stable: http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.30.y.git;a=commit;h=3c92900d9a4afb176d3de335dc0da0198660a244 mainline: http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=b8d966efd9a46a9a35beac50cbff6e30565125ef While not directly exploitable, its just needs write access to the sysfs files to get exploited, so I guess this warrants a CVE number. Ciao, Marcus
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.