Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 385923 (CVE-2011-2209)

Summary: Kernel: linux >= 2.6.39.1 signedness error when processing the "osf_getdomainname()" system call (CVE-2011-2209)
Product: Gentoo Security Reporter: Michael Harrison <n0idx80>
Component: KernelAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: trivial CC: alpha-kernel, kernel
Priority: Normal    
Version: unspecified   
Hardware: Alpha   
OS: Linux   
URL: http://secunia.com/advisories/44754/
Whiteboard: [linux >= 2.6.39.1]
Package list:
Runtime testing required: ---

Description Michael Harrison 2011-10-06 20:04:14 UTC
A signedness error when processing the "osf_getdomainname()" system call in arch/alpha/kernel/osf_sys.c can be exploited to disclose the contents of some kernel memory.
Comment 1 Michael Harrison 2012-01-31 10:54:31 UTC
Original Advisory:
https://lkml.org/lkml/2011/6/11/87

Solution:
Fixed in version 2.6.35.14

Sorry this old, but trying to clean up some kernel bugs.
Thanks,
Michael