lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <CAO5W59jZdDgSBE3Tr79u7TuCrdsirhisFxKH6aCH5oE4soOz1g@mail.gmail.com>
Date:   Thu, 12 Nov 2020 18:15:08 +0000
From:   John Boero <boeroboy@...il.com>
To:     Greg Kroah-Hartman <gregkh@...uxfoundation.org>
Cc:     Felipe Balbi <balbi@...nel.org>, linux-usb@...r.kernel.org,
        linux-kernel@...r.kernel.org
Subject: Re: [PATCH] usb: core: Null deref in kernel with USB webcams.

Then why does line 278 right below it check for NULL?

On Thu, Nov 12, 2020 at 5:56 PM Greg Kroah-Hartman
<gregkh@...uxfoundation.org> wrote:
>
> On Thu, Nov 12, 2020 at 05:13:30PM +0000, John Boero wrote:
> > Yes the patch is backwards sorry.  Testing alt proposal from
> > stern@...land.harvard.edu.  It may be a buggy driver
> > but it would be nice if a buggy driver couldn't bring down
> > the entire usb core. lsusb hangs until reboot or reset of usb.
>
> buggy kernel drivers can do anything, including deleting the contents of
> your disk.  We don't protect the kernel from itself, sorry :)
>
> good luck!
>
> greg k-h

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ