commit | 276bdb82dedb290511467a5a4fdbe9f0b52dce6f | [log] [tgz] |
---|---|---|
author | Mathias Krause <minipli@googlemail.com> | Wed Aug 15 11:31:54 2012 +0000 |
committer | David S. Miller <davem@davemloft.net> | Wed Aug 15 21:36:31 2012 -0700 |
tree | 0882e07c971f4254c5fe07c0e3eefadb8c6cfda0 | |
parent | 3592aaeb80290bda0f2cf0b5456c97bfc638b192 [diff] |
dccp: check ccid before dereferencing ccid_hc_rx_getsockopt() and ccid_hc_tx_getsockopt() might be called with a NULL ccid pointer leading to a NULL pointer dereference. This could lead to a privilege escalation if the attacker is able to map page 0 and prepare it with a fake ccid_ops pointer. Signed-off-by: Mathias Krause <minipli@googlemail.com> Cc: Gerrit Renker <gerrit@erg.abdn.ac.uk> Cc: stable@vger.kernel.org Signed-off-by: David S. Miller <davem@davemloft.net>