Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Date: Tue, 12 Jul 2011 11:20:23 +0800
From: Eugene Teo <eugene@...hat.com>
To: oss-security@...ts.openwall.com
CC: "Steven M. Christey" <coley@...us.mitre.org>
Subject: CVE-2011-2525 kernel: kernel: net_sched: fix qdisc_notify()

tc_fill_qdisc() should not be called for builtin qdisc, or it
dereference a NULL pointer to get device ifindex.

References:
http://kerneltrap.org/mailarchive/linux-netdev/2010/5/21/6277805
https://bugzilla.redhat.com/CVE-2011-2525

Upstream commit:
http://git.kernel.org/linus/53b0f08042f04813cd1a7473dacd3edfacb28eb3

Thanks, Eugene

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.