From: Greg KH <greg@kroah.com>
To: Johannes Berg <johannes@sipsolutions.net>
Cc: Kees Cook <kees.cook@canonical.com>,
linux-kernel@vger.kernel.org,
"John W. Linville" <linville@tuxdriver.com>,
"David S. Miller" <davem@davemloft.net>,
Eric Dumazet <eric.dumazet@gmail.com>,
Joe Perches <joe@perches.com>, Jean Tourrilhes <jt@hpl.hp.com>,
Tejun Heo <tj@kernel.org>,
linux-wireless@vger.kernel.org, netdev@vger.kernel.org
Subject: Re: [vendor-sec] [PATCH] wireless: fix 64K kernel heap content leak via ioctl
Date: Wed, 15 Sep 2010 16:28:04 -0700 [thread overview]
Message-ID: <20100915232804.GB25877@kroah.com> (raw)
In-Reply-To: <1284592267.3707.7.camel@jlt3.sipsolutions.net>
On Thu, Sep 16, 2010 at 01:11:07AM +0200, Johannes Berg wrote:
> On Wed, 2010-09-15 at 15:48 -0700, Greg KH wrote:
> > On Fri, Aug 27, 2010 at 02:02:41PM -0700, Kees Cook wrote:
> > > This problem was originally tracked down by Brad Spengler.
> > >
> > > When calling wireless ioctls, if a driver does not correctly
> > > validate/shrink iwp->length, the resulting copy_to_user can leak up to
> > > 64K of kernel heap contents.
> > >
> > > It seems that this is triggerable[1] in 2.6.32 at least on ath5k, but
> > > I was not able to track down how. The twisty maze of ioctl handlers
> > > stumped me. :) Other drivers I checked did not appear to have any problems,
> > > but the potential remains. I'm not sure if this patch is the right approach;
> > > it was fixed differently[2] in grsecurity.
> > >
> > > [1] http://forums.grsecurity.net/viewtopic.php?f=3&t=2290&start=0
> > > [2] http://grsecurity.net/~spender/wireless-infoleak-fix2.patch
> >
> > Is this fixed differently upstream in the kernel with commit id
> > 42da2f948d949efd0111309f5827bf0298bcc9a4?
>
> Yes, that's the fix for this.
Wonderful, thanks for letting me know.
greg k-h
prev parent reply other threads:[~2010-09-15 23:28 UTC|newest]
Thread overview: 23+ messages / expand[flat|nested] mbox.gz Atom feed top
2010-08-27 21:02 [PATCH] wireless: fix 64K kernel heap content leak via ioctl Kees Cook
2010-08-27 21:22 ` Jean Tourrilhes
2010-08-27 21:43 ` Kees Cook
2010-08-27 21:53 ` Jean Tourrilhes
2010-08-27 21:53 ` Jean Tourrilhes
2010-08-27 22:35 ` Luis R. Rodriguez
2010-08-27 22:39 ` Jean Tourrilhes
2010-08-27 22:39 ` Jean Tourrilhes
2010-08-27 22:51 ` Luis R. Rodriguez
2010-08-30 8:47 ` Johannes Berg
2010-08-30 8:58 ` Johannes Berg
2010-08-30 9:59 ` Johannes Berg
2010-08-30 10:24 ` [PATCH] wireless extensions: fix kernel heap content leak Johannes Berg
2010-08-30 18:03 ` Kees Cook
2010-08-30 18:03 ` Kees Cook
2010-08-30 18:06 ` Johannes Berg
2010-08-30 17:40 ` [PATCH] wireless: fix 64K kernel heap content leak via ioctl Jean Tourrilhes
2010-08-30 17:50 ` Johannes Berg
2010-08-30 17:50 ` Johannes Berg
2010-09-15 22:48 ` [vendor-sec] " Greg KH
2010-09-15 23:11 ` Johannes Berg
2010-09-15 23:11 ` Johannes Berg
2010-09-15 23:28 ` Greg KH [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20100915232804.GB25877@kroah.com \
--to=greg@kroah.com \
--cc=davem@davemloft.net \
--cc=eric.dumazet@gmail.com \
--cc=joe@perches.com \
--cc=johannes@sipsolutions.net \
--cc=jt@hpl.hp.com \
--cc=kees.cook@canonical.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-wireless@vger.kernel.org \
--cc=linville@tuxdriver.com \
--cc=netdev@vger.kernel.org \
--cc=tj@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.