The tomoyo_mount_acl function in security/tomoyo/mount.c in the Linux kernel before 2.6.39.2 calls the kern_path function with arguments taken directly from a mount system call, which allows local users to cause a denial of service (OOPS) or possibly have unspecified other impact via a NULL value for the device name.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://www.openwall.com/lists/oss-security/2011/07/01/5 | third party advisory mailing list |
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=4e78c724d47e2342aa8fde61f6b8536f662f795f | |
https://github.com/torvalds/linux/commit/4e78c724d47e2342aa8fde61f6b8536f662f795f | third party advisory patch |
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39.2 | broken link |
http://marc.info/?l=bugtraq&m=139447903326211&w=2 | third party advisory vendor advisory |