lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <20101206221345.GG4187@barata.holoscopio.com>
Date:	Mon, 6 Dec 2010 20:13:46 -0200
From:	Thadeu Lima de Souza Cascardo <cascardo@...oscopio.com>
To:	Matthew Garrett <mjg59@...f.ucam.org>
Cc:	platform-driver-x86@...r.kernel.org, linux-kernel@...r.kernel.org,
	carlos@...angeworlds.co.uk, stable@...nel.org, ceolin@...vel.com
Subject: Re: [PATCH] wmi: use memcmp instead of strncmp to compare GUIDs

On Mon, Dec 06, 2010 at 10:02:31PM +0000, Matthew Garrett wrote:
> Applied to -next, thanks.
> 
> -- 
> Matthew Garrett | mjg59@...f.ucam.org

Hello, Matthew.

I consider this one a serious bug and with a trivial fix that should go
to Linus, for the next release candidate. I also consider it should go
to stable releases, and that's why I'm copying stable.

Any out-of-tree wmi driver written for systems with two or more GUIDs
containing any '\0' byte with a common prefix will fail to load because
of this bug. I've hit that, and that's how I found the bug.

Regards,
Cascardo.

Download attachment "signature.asc" of type "application/pgp-signature" (837 bytes)

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ