Bug 127256

Summary: CAN-2004-0619 Broadcom 5820 integer overflow
Product: Red Hat Enterprise Linux 2.1 Reporter: Mark J. Cox <mjc>
Component: kernelAssignee: Nalin Dahyabhai <nalin>
Status: CLOSED ERRATA QA Contact: Brian Brock <bbrock>
Severity: medium Docs Contact:
Priority: medium    
Version: 2.1CC: benl, dff, jparadis, laroche, mwesley, nalin, riel
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: i386   
OS: Linux   
URL: http://marc.theaimsgroup.com/?l=bugtraq&m=108802653409053
Whiteboard: impact=moderate,public=20040623
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2005-04-28 15:05:10 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Attachments:
Description Flags
bcm5820-update-rhel21.patch none

Description Mark J. Cox 2004-07-05 10:58:03 UTC
Reported to Bugtraq on Jun23.  

An integer overflow in the ubsec_keysetup function for Linux Broadcom
5820 cryptonet driver allows local users to cause a denial of service
(crash) and possibly execute arbitrary code via a negative
add_dsa_buf_bytes variable, which leads to a buffer overflow.

See also http://secunia.com/advisories/11936/

Comment 1 Jim Paradis 2004-11-29 21:28:47 UTC
See also Bug 127258


Comment 2 John W. Linville 2004-12-15 17:15:34 UTC
Created attachment 108634 [details]
bcm5820-update-rhel21.patch

Patch brings RHEL2.1 BCM5820 driver in sync with version in RHEL3.

Comment 3 John W. Linville 2004-12-15 17:40:29 UTC
Unfortunately, above patch does not appear to actually work... :-(

Comment 4 John W. Linville 2004-12-20 16:02:01 UTC
Well, I seem to have spoken too soon...the above patch DOES work,
provided that the "bcm5820" package is replaced with the later
"hwcrypto" package.

I'm going to propose the above patch on the proviso that the RHEL2.1
update includes the "hwcrypto" package rather than the "bcm5820"
package (or an updated "bcm5820" package that takes the bcm5820
portions of the "hwcrypto" package).

Comment 14 John Flanagan 2005-04-28 15:05:10 UTC
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.

http://rhn.redhat.com/errata/RHSA-2005-283.html