Bug 248710

Summary: Local keyboard DoS through LED switching
Product: [Other] Security Response Reporter: Marcel Holtmann <holtmann>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: dhoward, jpirko, kernel-mgr, kseifried, lwang, peterm, vgoyal
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2011-09-28 17:14:18 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 461232, 461233, 461239, 461240    
Bug Blocks:    
Attachments:
Description Flags
Upstream patch for this issue none

Description Marcel Holtmann 2007-07-18 12:40:16 UTC
On some boxes keyboard controllers are too slow to withstand continuous flow of
requests to turn keyboard LEDs on and off and start losing some keypresses or
even all of them. This causes a local denial of service situation.

Comment 5 Eugene Teo (Security Response) 2008-09-05 08:49:03 UTC
Created attachment 315849 [details]
Upstream patch for this issue

Comment 6 Eugene Teo (Security Response) 2008-09-05 09:01:23 UTC
Reproducer:
while true; do setleds +num; setleds -num; done

http://lkml.org/lkml/2007/6/15/22

Comment 13 Kurt Seifried 2011-09-28 17:14:18 UTC
This issue has been addressed in following products:

  Red Hat Linux Enterprise 4
  Red Hat Linux Enterprise 4.7.z
  Red Hat Linux Enterprise 5

Via RHSA-2009-0014 available at https://rhn.redhat.com/errata/RHSA-2009-0014.html and RHSA-2008:1017 available at https://rhn.redhat.com/errata/RHSA-2008-1017.html