CVE-2011-2700
Publication date 6 September 2011
Last updated 24 July 2024
Ubuntu priority
Multiple buffer overflows in the si4713_write_econtrol_string function in drivers/media/radio/si4713-i2c.c in the Linux kernel before 2.6.39.4 on the N900 platform might allow local users to cause a denial of service or have unspecified other impact via a crafted s_ext_ctrls operation with a (1) V4L2_CID_RDS_TX_PS_NAME or (2) V4L2_CID_RDS_TX_RADIO_TEXT control ID.
From the Ubuntu Security Team
Mauro Carvalho Chehab discovered that the si4713 radio driver did not correctly check the length of memory copies. If this hardware was available, a local attacker could exploit this to crash the system or gain root privileges.
Status
Package | Ubuntu Release | Status |
---|---|---|
linux | 14.04 LTS trusty |
Not affected
|
linux-ec2 | 14.04 LTS trusty | Not in release |
linux-flo | 14.04 LTS trusty | Not in release |
linux-fsl-imx51 | 14.04 LTS trusty | Not in release |
linux-goldfish | 14.04 LTS trusty | Not in release |
linux-grouper | 14.04 LTS trusty | Not in release |
linux-lts-backport-maverick | 14.04 LTS trusty | Not in release |
linux-lts-backport-natty | 14.04 LTS trusty | Not in release |
linux-lts-backport-oneiric | 14.04 LTS trusty | Not in release |
linux-maguro | 14.04 LTS trusty | Not in release |
linux-mako | 14.04 LTS trusty | Not in release |
linux-manta | 14.04 LTS trusty | Not in release |
linux-mvl-dove | 14.04 LTS trusty | Not in release |
linux-ti-omap4 | 14.04 LTS trusty | Not in release |
References
Related Ubuntu Security Notices (USN)
- USN-1208-1
- Linux kernel (Marvel DOVE) vulnerabilities
- 14 September 2011
- USN-1219-1
- Linux kernel (Maverick backport) vulnerabilities
- 29 September 2011
- USN-1228-1
- Linux kernel (OMAP4) vulnerabilities
- 12 October 2011
- USN-1246-1
- Linux kernel vulnerabilities
- 25 October 2011
- USN-1203-1
- Linux kernel (Marvel DOVE) vulnerabilities
- 13 September 2011
- USN-1220-1
- Linux kernel (OMAP4) vulnerabilities
- 29 September 2011
- USN-1218-1
- Linux kernel vulnerabilities
- 29 September 2011
- USN-1227-1
- Linux kernel vulnerabilities
- 11 October 2011
- USN-1256-1
- Linux kernel (Natty backport) vulnerabilities
- 9 November 2011
- USN-1216-1
- Linux kernel (EC2) vulnerabilities
- 26 September 2011