[CVE-2016-3951][xenial][PATCH 0/2] usbnet: memory corruption triggered by invalid USB descriptor

Luis Henriques luis.henriques at canonical.com
Wed Apr 20 10:15:10 UTC 2016


Following this email I'm sending the 2 patches that should fix
CVE-2016-3951 on xenial.

Bjørn Mork (1):
  cdc_ncm: do not call usbnet_link_change from cdc_ncm_bind

Oliver Neukum (1):
  usbnet: cleanup after bind() in probe()

 drivers/net/usb/cdc_ncm.c | 20 +++++---------------
 drivers/net/usb/usbnet.c  |  7 +++++++
 2 files changed, 12 insertions(+), 15 deletions(-)





More information about the kernel-team mailing list