Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Sun, 30 Aug 2009 19:15:34 +0800
From: Eugene Teo <>
CC: Greg KH <>
Subject: Re: CVE-2009-2698 kernel: udp socket NULL ptr dereference

Eugene Teo wrote:
> A flaw was found in the udp_sendmsg() implementation in the Linux kernel 
> when using the MSG_MORE flag on UDP sockets. A local, unprivileged user 
> could use this flaw to cause a local denial of service or escalate their 
> privileges. This was fixed by Herbert Xu in v2.6.19-rc1, and reported by 
> Tavis Ormandy and Julien Tinnes of the Google Security Team.
> Upstream commits:
> References:

Related to this:
Add a check in ip_append_data() for NULL *rtp to prevent future bugs in 
callers from being exploitable.

Thanks, Eugene

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.