Home page logo

oss-sec logo oss-sec mailing list archives

Re: CVE Request: kernel - sock_diag: Fix out-of-bounds access to sock_diag_handlers[]
From: Dan Rosenberg <dan.j.rosenberg () gmail com>
Date: Mon, 25 Feb 2013 14:07:42 -0500

On 02/25/2013 01:59 PM, Mathias Krause wrote:
On Mon, Feb 25, 2013 at 7:53 PM, Dan Rosenberg
<dan.j.rosenberg () gmail com> wrote:
On 02/25/2013 01:45 PM, Mathias Krause wrote:
Did you even try to run the exploit on a v3.2 kernel? Or even more
simple, looked at the code of a v3.2 kernel? There is no sock_diag
anywhere in the kernel; there is only inet_diag. And inet_diag hadn't
and still does not have the out-of-bounds access issue. So no, this
bug is non-existent on a v3.2 kernel.


The bug was introduced with this commit:

This commit took place during kernel version 3.2.0-rc4, so yes, it does
seem to affect 3.2 kernels.

$ git describe --contains d366477a52f1df29fa066ffb18e4e6101ee2ad04

Is git lying to me or what?


Apparently so. Linux 3.3-rc1 was released on January 19, 2012, while the
patch to introduce sock_diag was applied December 6, 2011.


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]