Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Fri, 18 Mar 2011 07:18:30 -0400
From: Dan Rosenberg <>
Subject: CVE request: kernel: AudioScience HPI driver

"The user-supplied index into the adapters array needs to be checked, or
an out-of-bounds kernel pointer could be accessed and used, leading to
potentially exploitable memory corruption."

This may be triggered by a user with access to an appropriate device
file, which I'd expect would be restricted to group 'audio'.  And
you'd need to have this particular driver loaded, either by using the
appropriate hardware or finding a new way to force it to be loaded in
violation of security policy.



Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.