Skip to content
Commit d846f711 authored by Vasiliy Kulikov's avatar Vasiliy Kulikov Committed by Patrick McHardy
Browse files

bridge: netfilter: fix information leak



Struct tmp is copied from userspace.  It is not checked whether the "name"
field is NULL terminated.  This may lead to buffer overflow and passing
contents of kernel stack as a module name to try_then_request_module() and,
consequently, to modprobe commandline.  It would be seen by all userspace
processes.

Signed-off-by: default avatarVasiliy Kulikov <segoon@openwall.com>
Signed-off-by: default avatarPatrick McHardy <kaber@trash.net>
parent 44bd4de9
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment