From: Kees Cook Date: Fri, 10 May 2013 21:48:21 +0000 (-0700) Subject: b43: stop format string leaking into error msgs X-Git-Tag: v3.2.47~14 X-Git-Url: http://git.openpandora.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=bfb624e7fd41437a2c256adaf4041fe4414f8f26;p=pandora-kernel.git b43: stop format string leaking into error msgs commit e0e29b683d6784ef59bbc914eac85a04b650e63c upstream. The module parameter "fwpostfix" is userspace controllable, unfiltered, and is used to define the firmware filename. b43_do_request_fw() populates ctx->errors[] on error, containing the firmware filename. b43err() parses its arguments as a format string. For systems with b43 hardware, this could lead to a uid-0 to ring-0 escalation. CVE-2013-2852 Signed-off-by: Kees Cook Signed-off-by: John W. Linville Signed-off-by: Ben Hutchings --- Reading git-diff-tree failed