Bug 482866 (CVE-2009-0322)

Summary: CVE-2009-0322 kernel: dell_rbu local oops
Product: [Other] Security Response Reporter: Mark J. Cox <mjc>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: anton, bhu, bressers, dhoward, jpirko, kseifried, lgoncalv, lwang, vgoyal, williams
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2011-09-30 22:50:00 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 482937, 482938, 482939, 482940, 482941, 482942    
Bug Blocks:    

Description Mark J. Cox 2009-01-28 16:22:09 UTC
Upstream kernel commit 81156928f8fe31621e467490b9d441c0285998c3 addressed an issue:

    dell_rbu: use scnprintf() instead of less secure sprintf()

    Reading 0 bytes from /sys/devices/platform/dell_rbu/image_type or
    /sys/devices/platform/dell_rbu/packet_size by an ordinary user causes an
    oops.

dell_rbu is "Remote Bio Update driver for Dell systems"

We ship dell_rbu with Red Hat Enterprise Linux 3 and later and they are potentially affected by this issue.  

Note however that this issue can only be triggered on Dell systems that have this driver loaded.

Comment 12 errata-xmlrpc 2009-03-12 14:41:29 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 4

Via RHSA-2009:0331 http://rhn.redhat.com/errata/RHSA-2009:0331.html

Comment 13 errata-xmlrpc 2009-03-27 00:14:44 UTC
This issue has been addressed in following products:

  MRG for RHEL-5

Via RHSA-2009:0360 https://rhn.redhat.com/errata/RHSA-2009-0360.html

Comment 14 errata-xmlrpc 2009-04-01 08:30:55 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 5

Via RHSA-2009:0326 https://rhn.redhat.com/errata/RHSA-2009-0326.html