Re: [PATCH] brcmfmac: add length check in brcmf_cfg80211_escan_handler()

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Thu, Oct 12, 2017 at 11:54:12AM +0200, Arend van Spriel wrote:
> commit 17df6453d4be17910456e99c5a85025aa1b7a246 upstream.
> 
> Upon handling the firmware notification for scans the length was
> checked properly and may result in corrupting kernel heap memory
> due to buffer overruns. This fix addresses CVE-2017-0786.
> 
> Cc: Kevin Cernekee <cernekee@xxxxxxxxxxxx>
> Reviewed-by: Hante Meuleman <hante.meuleman@xxxxxxxxxxxx>
> Reviewed-by: Pieter-Paul Giesberts <pieter-paul.giesberts@xxxxxxxxxxxx>
> Reviewed-by: Franky Lin <franky.lin@xxxxxxxxxxxx>
> Signed-off-by: Arend van Spriel <arend.vanspriel@xxxxxxxxxxxx>
> ---
> Hi, Greg
> 
> This backport for stable-4.4 has been compile tested on x86_64 on
> linux-4.4.y branch in the stable repo. Apparently I only checked
> that the patch applied on 4.4. Lesson learned.

No worries, thanks for the patch.

greg k-h



[Index of Archives]     [Linux Kernel]     [Kernel Development Newbies]     [Linux USB Devel]     [Video for Linux]     [Linux Audio Users]     [Yosemite Hiking]     [Linux Kernel]     [Linux SCSI]