Back

MEDIUM

kernel: interger overflows in Sbus PROM driver

Published Oct 9, 2007

Description

Multiple integer overflows in Sbus PROM driver (drivers/sbus/char/openprom.c) for the Linux kernel 2.4.x up to 2.4.27, 2.6.x up to 2.6.7, and possibly later versions, allow local users to execute arbitrary code by specifying (1) a small buffer size to the copyin_string function or (2) a negative buffer size to the copyin function.

Affected products

Remediation

Red Hat statement

Not vulnerable. The Linux kernel as shipped with with Red Hat Enterprise Linux 2.1, 3, 4 and 5 did not include the Sbus PROM module and therefore are not affected by this issue.

Metrics

Weaknesses (1)

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 9, 2007
Updated Aug 8, 2024
Reserved Oct 8, 2007
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Dec 31, 2004