verify the underlying transport exists before creating a connection in kernel-rds CVE-2015-6937 remote
asked 2017-07-20 11:41:22 +0200
This post is a wiki. Anyone with karma >75 is welcome to improve it.
The __rds_conn_create function in net/rds/connection.c in the Linux kernel through 4.2.3 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by using a socket that was not properly bound. CVSS v2 Base Score: 7.8 HIGH (attack range: remote)
Upstream-commit and 3.2-backport are equal, so implementing in kernel-3.4 for jolla1 should be no problem ...
File affected: kernel-adaptation-sbj-3.4.108.20161101.1/net/rds/connection.c lines 178-183
@jovirkku this should have a "tracked by jolla" label
lpr ( 2017-09-19 09:40:33 +0200 )edit