[prev in list] [next in list] [prev in thread] [next in thread] 

List:       oss-security
Subject:    Re: [oss-security] md raid null ptr dereference (when sysfs is writable)
From:       Eugene Teo <eugene () redhat ! com>
Date:       2009-07-26 3:18:05
Message-ID: 4A6BCAED.60301 () redhat ! com
[Download RAW message or body]

Marcus Meissner wrote:
> Hi,
> 
> http://xorl.wordpress.com/2009/07/21/linux-kernel-md-driver-null-pointer-dereference/
> 
> 2.6.30 stable:
> http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.30.y.git;a=commit;h=3c92900d9a4afb176d3de335dc0da0198660a244
>  mainline:
> http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=b8d966efd9a46a9a35beac50cbff6e30565125ef
>  
> While not directly exploitable, its just needs write access to the sysfs files
> to get exploited, so I guess this warrants a CVE number.

Note that the default permission for this sysfs file is 644. It can be
triggered if you are a local privileged user.

Thanks, Eugene


[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic