4 ms·
Four Remote Packet-Of-Death Vulnerabilities Found in Linux Driver
- zx2c4 11y agoRelated oss-sec discussion for CVE assignment: http://seclists.org/oss-sec/2015/q2/446 http://seclists.org/oss-sec/2015/q2/446
- cjbprime 11y agoIt's a "staging" driver; not a big deal, you are almost certainly not using this driver.
- zx2c4 11y agoI wouldn't jump to such conclusions so fast about the deployment and usage of this driver. Included with many distributions and several devices require its usage.
- cjbprime 11y agoIt doesn't look to be enabled in Fedora, Debian, Ubuntu, Mint or OpenSuSE to me, which covers the top five. Which distributions are you referring to? I see OpenSUSE disabled it back in 2013 with a commit message '"Take it behind the barn and shoot it." says Michal. :)', presumably in response to inspection after its previous vulnerabilities -- http://kernel.opensuse.org/cgit/kernel-source/commit/?id=2c1c77c5da1ce2e3efb4555261fa2d05f4565ff7 http://kernel.opensuse.org/cgit/kernel-source/commit/?id=2c1...
- tedchs 11y agoAlarmist headline for an obscure driver, that, while included in the kernel, is almost certainly not running on your production Linux server. Seems to be related to products from Ozmo Device Inc. that push USB data over a layer 2 Wi-Fi Direct connection: http://lxr.free-electrons.com/source/drivers/staging/ozwpan/ http://lxr.free-electrons.com/source/drivers/staging/ozwpan/
- duskwuff 11y agoFrom a company that doesn't even appear to be in business anymore: http://www.ozmodevices.com/ http://www.ozmodevices.com/