From: Kees Cook Date: Fri, 10 May 2013 21:48:21 +0000 (-0700) Subject: b43: stop format string leaking into error msgs X-Git-Tag: v3.10-rc6~18^2^2^2 X-Git-Url: http://git.openpandora.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=e0e29b683d6784ef59bbc914eac85a04b650e63c;p=pandora-kernel.git b43: stop format string leaking into error msgs The module parameter "fwpostfix" is userspace controllable, unfiltered, and is used to define the firmware filename. b43_do_request_fw() populates ctx->errors[] on error, containing the firmware filename. b43err() parses its arguments as a format string. For systems with b43 hardware, this could lead to a uid-0 to ring-0 escalation. CVE-2013-2852 Signed-off-by: Kees Cook Cc: stable@vger.kernel.org Signed-off-by: John W. Linville --- Reading git-diff-tree failed