|
Message-ID: <CAG_fn=UmeU0K9HRVz1mrkxsTejVHMMG3fwrxWdcwMCpTrR8hYw@mail.gmail.com>
Date: Tue, 20 Jun 2017 17:35:00 +0200
From: Alexander Potapenko <glider@...gle.com>
To: oss-security@...ts.openwall.com
Subject: Re: Linux kernel 2.6.0 to 4.12-rc4 infoleak due to a
data race in ALSA timer
On Tue, Jun 13, 2017 at 5:18 PM, Adam Maris <amaris@...hat.com> wrote:
>
>> > https://github.com/torvalds/linux/commit/d11662f4f798b50d8c8743f43384
> 2c3e40fe3378
>> > https://github.com/torvalds/linux/commit/ba3021b2c79b2fa9114f92790a99
> deb27a65b728
>>
>>
>
> For reference, CVE-2017-1000380 was assigned for this issue.
>
> Regards,
>
> --
> Adam Mariš, Red Hat Product Security
> 1CCD 3446 0529 81E3 86AF 2D4C 4869 76E7 BEF0 6BC2
Please find the PoC exploit attached.
--
Alexander Potapenko
Software Engineer
Google Germany GmbH
Erika-Mann-Straße, 33
80636 München
Geschäftsführer: Matthew Scott Sucherman, Paul Terence Manicle
Registergericht und -nummer: Hamburg, HRB 86891
Sitz der Gesellschaft: Hamburg
View attachment "snd_timer.c" of type "text/x-csrc" (7623 bytes)
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.