Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Sun, 21 Jul 2019 11:03:01 -0700
From: Linus Torvalds <>
To: Tavis Ormandy <>, Bartlomiej Zolnierkiewicz <>, 
	Daniel Vetter <>
Subject: Re: stack buffer overflow in fbdev

Completely untested patch attached. There are probably better ways to do this.

Adding the proper people to the cc, and quoting Tavis' email in its entirety.

Daniel - you got added despite not being explicitly listed as
maintainer because you've touched fbdev/core/ more than most lately,
plus you know edid anyway. As such: "tag, you're it, sucker".


On Sat, Jul 20, 2019 at 5:35 PM Tavis Ormandy <> wrote:
> Hello, during a conversation on twitter we noticed a stack buffer
> overflow in fbdev with malicious edid data:
> There is enough space to have 52 1-byte length values, which makes svd_n
> 52, then make the final value length 0x1f (the maximum), which makes
> svd_n 83 and overflows the 64 byte stack buffer svd[] with controlled
> data.
> This requires a malicious monitor / projector / etc, so pretty low impact.
> I pulled out the code to make a demo (I removed the checksum, but it
> doesnt prevent the bug):
> This was discovered by Nico Waisman of Semmle.
> Tavis.
> --
> -------------------------------------
> | finger me for my pgp key.
> -------------------------------------------------------

View attachment "patch.diff" of type "text/x-patch" (942 bytes)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.