First published: Tue Jan 25 2011(Updated: )
If the iowarrior devices in this case statement support more than 8 bytes per report, it is possible to write past the end of a kernel heap allocation. This will probably never be possible, but change the allocation to be more defensive anyway. Upstream commit: <a href="http://git.kernel.org/linus/3ed780117dbe5acb64280d218f0347f238dafed0">http://git.kernel.org/linus/3ed780117dbe5acb64280d218f0347f238dafed0</a> Acknowledgements: Red Hat would like to thank Kees Cook for reporting this issue.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Linux kernel | <2.6.37 | |
Canonical Ubuntu Linux | =8.04 | |
debian/linux-2.6 | ||
debian/user-mode-linux |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.