Bug 396751 (CVE-2007-6694)

Summary: CVE-2007-6694 /proc/cpuinfo DoS on some ppc machines
Product: [Other] Security Response Reporter: Jan Lieskovsky <jlieskov>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: kreilly, kseifried, williams
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard: reported=20071123,public=20071123,source=lkml,impact=moderate
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2011-09-29 18:03:56 EDT Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Bug Depends On: 396771, 396781, 396791, 396801, 396811, 396821, 396831    
Bug Blocks:    
Attachments:
Description Flags
Patch from the reporter. none

Description Jan Lieskovsky 2007-11-23 08:46:00 EST
Description of problem:

This patch does fix possible NULL pointer dereference
inside of strncmp() if of_get_property() failed. 

This issue went public via: 

http://groups.google.com/group/linux.kernel/browse_thread/thread/d3573f2b305c1e6e?hl=en#d13e0770eadc48c5
Comment 1 Jan Lieskovsky 2007-11-23 08:46:48 EST
This one has not CVE number assigned yet, will update this one as soon as
this gets one. 
Comment 2 Jan Lieskovsky 2007-11-23 08:49:34 EST
Created attachment 267541 [details]
Patch from the reporter.

Attaching patch from the reporter.