[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <20090718150909.GA1191@khazad-dum.debian.net>
Date: Sat, 18 Jul 2009 12:09:09 -0300
From: Henrique de Moraes Holschuh <hmh@....eng.br>
To: Michael Buesch <mb@...sch.de>
Cc: linux-kernel@...r.kernel.org
Subject: Re: [PATCH] nvram: Fix root triggerable integer overflow crash
On Sat, 18 Jul 2009, Michael Buesch wrote:
> This bug probably is exploitable by overwriting the function return address or something
> like that. But let's hope there's no distribution out there with user write permissions
> on the /dev/nvram node. So it's probably only exploitable by root.
I have seen setups with group-writeable /dev/nvram to support some (old!)
thinkpad utilities.
Even if it cannot be exploited for more than a DoS, IMO that's still bad
enough to warrant fixing this also on stable kernels if they are vulnerable.
So, does the fix also apply to 2.6.27+ ? If it does, please send it to
stable@...nel.org as well.
--
"One disk to rule them all, One disk to find them. One disk to bring
them all and in the darkness grind them. In the Land of Redmond
where the shadows lie." -- The Silicon Valley Tarot
Henrique Holschuh
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@...r.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/
Powered by blists - more mailing lists