Re: [PATCH 0/1] ieee802154: ca8210: Fix potential security exploit

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Please ignore this for the time being, I'll be issuing a v2 soon...

Harry


On 27/03/2018 14:45, harrymorris12@xxxxxxxxx wrote:
From: Harry Morris <h.morris@xxxxxxxxxxx>

This patchset fixes a small bug in the ca8210 driver discovered by Domen Puncer Kugler <domen.puncer@xxxxxxxxxxx>.

The bug allows for uninitialised memory to be sent out over SPI by writing unexpected commands to the debug interface. The bug is described in more detail in 1/1.

This fix has been tested on a Raspberry Pi running kernel 4.9.37-v7+:

harry@raspberrypi:~ $ sudo bash -c 'echo -ne "\x4f\x10" > /sys/kernel/debug/ca8210'
bash: line 0: echo: write error: Message too long
harry@raspberrypi:~ $

Harry Morris (1):
   ieee802154: ca8210: fix uninitialised data read

  drivers/net/ieee802154/ca8210.c | 7 +++++++
  1 file changed, 7 insertions(+)

--
To unsubscribe from this list: send the line "unsubscribe linux-wpan" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at  http://vger.kernel.org/majordomo-info.html



[Index of Archives]     [Linux NFS]     [Linux NILFS]     [Linux USB Devel]     [Linux Audio Users]     [Photo]     [Yosemite News]     [Linux Kernel]     [Linux SCSI]

  Powered by Linux