DescriptionEugene Teo (Security Response)
2010-09-22 03:58:39 UTC
Description of problem:
While reviewing commit 1c40be12f7d8ca1d387510d39787b12e512a7ce8 (CVE-2010-2942), Jeff Mahoney audited other users of tc_action_ops->dump for information leaks.
That commit covered almost all of them but act_police still had a leak.
opt.limit and opt.capab aren't zeroed out before the structure is passed out.
Upstream commit:
http://git.kernel.org/linus/0f04cfd098fb81fded74e78ea1a1b86cc6c6c31e