Kees Cook e0e29b683d b43: stop format string leaking into error msgs
The module parameter "fwpostfix" is userspace controllable, unfiltered,
and is used to define the firmware filename. b43_do_request_fw() populates
ctx->errors[] on error, containing the firmware filename. b43err()
parses its arguments as a format string. For systems with b43 hardware,
this could lead to a uid-0 to ring-0 escalation.

CVE-2013-2852

Signed-off-by: Kees Cook <keescook@chromium.org>
Cc: stable@vger.kernel.org
Signed-off-by: John W. Linville <linville@tuxdriver.com>
2013-06-12 10:20:59 -04:00
..
2012-05-16 12:45:21 -04:00
2013-05-08 17:15:06 -04:00
2013-03-06 16:28:59 -05:00
2012-08-06 14:56:35 -04:00
2013-04-23 12:27:56 +02:00
2013-04-23 12:27:57 +02:00
2013-04-23 12:27:57 +02:00
2012-12-10 15:49:59 -05:00
2012-08-06 14:56:35 -04:00
2012-08-06 14:56:35 -04:00
2012-12-06 15:04:56 -05:00
2013-04-23 12:27:58 +02:00
2013-04-23 12:27:58 +02:00
2012-11-13 21:43:55 +01:00
2011-11-07 13:19:12 -05:00