Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <20090126200744.GP21473@genesis.frugalware.org>
Date: Mon, 26 Jan 2009 21:07:44 +0100
From: Miklos Vajna <vmiklos@...galware.org>
To: oss-security@...ts.openwall.com
Subject: CVE request -- Linux kernel irda driver buffer overflow

Hi,

A buffer overflow has been recently fixed in the Linux kernel irda
driver.

Upstream bug:

http://bugzilla.kernel.org/show_bug.cgi?id=12397

Upstream fix:

http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=2950e952920811be465ec95c6b56f03dc66a05c0

From a quick analysis it was introduced in commit
8ef80aef118e405f2b6505f623830e6e73224f85, so versions >= 2.6.18 are
affected.

Thanks.

Content of type "application/pgp-signature" skipped

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.