mailing list archives
CVE request: kernel: xfs heap overflow
From: Xi Wang <xi.wang () gmail com>
Date: Tue, 10 Jan 2012 13:57:01 -0500
Commit ef14f0c1578dce4b688726eb2603e50b62d6665a introduced an integer
overflow in the ACL handling code, which could further lead to
heap-based buffer overflow via a crafted filesystem.
Both commits are needed to fix the vulnerability.
The vulnerability seems to first appear in 2.6.32-rc1. 3.2 contains
only the first commit.
- CVE request: kernel: xfs heap overflow Xi Wang (Jan 10)