lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Date:   Fri, 2 Feb 2018 10:00:41 +0000
From:   James Chapman <jchapman@...alix.com>
To:     netdev@...r.kernel.org
Subject: l2tp: fixes for syzbot reports - in progress

I'm currently working on fixes for various l2tp problems reported by
syzbot. If anyone else is also working on this, please get back to me
so that we can avoid duplicate effort.

The syzbot reports are:
9df43faf0 KASAN: use-after-free Read in pppol2tp_connect
6e6a5ec8d general protection fault in pppol2tp_connect
065d0fc35 KASAN: use-after-free Read in l2tp_session_create
347bd5acd KASAN: use-after-free Read in inet_shutdown
c8e66da87 KASAN: out-of-bounds Read in ip6_xmit
19c09769f WARNING in debug_print_object

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ