Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <929915505.18990807.1455190810330.JavaMail.zimbra@redhat.com>
Date: Thu, 11 Feb 2016 06:40:10 -0500 (EST)
From: Wade Mealing <wmealing@...hat.com>
To: OSS Security List <oss-security@...ts.openwall.com>
Cc: cve-assign@...re.org
Subject: Linux kernel: Flaw in CXGB3 driver.

Gday,

I would like a CVE for the following issue:

A flaw was found in the CXGB3 kernel driver when the network was considered congested.  The kernel would incorrectly misinterpret the congestion as an error condition and incorrectly free/clean up the skb. When the device would then send the skb's queued, these structures would be referenced and may panic the system or allow an attacker to escalate privileges in a use-after-free scenario.

The bug and the problematic free is shown shown in the patch[1]: 

----

The cxgb3_*_send() functions return NET_XMIT_ values, which are
positive integers values. So don't treat positive return values
as an error.
----

Thanks,

Wade Mealing
Red Hat Product Security Team

== References:

Upstream fix commit[1]:
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=67f1aee6f45059fd6b0f5b0ecb2c97ad0451f6b3

Red Hat bug:
https://bugzilla.redhat.com/show_bug.cgi?id=1303532

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.