Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Sun, 24 Jan 2016 03:51:44 +0800
From: Shawn <>
Cc: Pray3r Z <>
Subject: CVE request for prima wlan driver: Address buffer overflow due to
 invalid length


One exploitable bug has been fixed in prima wlan driver a few months

Upstream fix:

Cyanogenmod's backport fix:

It was lacking a check for valid length of copy a buffer, which can be
crafted by userspace. The application could communicate with wlan
driver via ioctl() with 0x8bf7 to enter into vulnerable code path.

This issue may leads to a local DoS or privilege escalation. Some
android phone/tablet are still using the vulnerable version of prima
driver. We've aware of android-msm-flo-3.4-marshmallow for Nexus 7(
2013) is affected by this isuee:

Plz review the file:


Then we've already sent a patch to backport fix for the branch and
still doesn't get any answer yet:!/#F0


Panic log:


We haven't exmine if this issue can be exploited to gain the root
privileges. But some fancy mitigation like PXN is not support well for
android armv7. Porting PaX UDEREF is an another option.

GNU powered it...
GPL protect it...
God blessing it...


View attachment "wext_poc.c" of type "text/x-csrc" (1811 bytes)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.