Date: Thu, 30 Mar 2017 14:55:42 +0300 From: Alexander Popov <alex.popov@...ux.com> To: oss-security@...ts.openwall.com Subject: Re: Linux kernel: CVE-2017-2636: local privilege escalation flaw in n_hdlc On 07.03.2017 20:45, Alexander Popov wrote: > This is an announcement of CVE-2017-2636, which is a race condition in > the n_hdlc Linux kernel driver (drivers/tty/n_hdlc.c). It can be exploited > to gain a local privilege escalation. > > This driver provides HDLC serial line discipline and comes as a kernel module > in many Linux distributions, which have CONFIG_N_HDLC=m in the kernel config. Hello, I've published the write-up: https://a13xp0p0v.github.io/2017/03/24/CVE-2017-2636.html -- Alexander
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.