Re: [PATCH 0/4] USB over IP Secuurity fixes

2017-12-08 Thread Shuah Khan
On 12/08/2017 09:33 AM, Greg KH wrote: > On Fri, Dec 08, 2017 at 08:44:58AM -0700, Shuah Khan wrote: >> Hi Jakub, >> >> On 12/08/2017 08:14 AM, Secunia Research wrote: >>> Hi Shuah, >>> >>> Thanks a lot for the quick fixes. >> >> Thanks for finding them and doing all the leg work in >> pin

Re: [PATCH 0/4] USB over IP Secuurity fixes

2017-12-08 Thread Greg KH
On Fri, Dec 08, 2017 at 08:44:58AM -0700, Shuah Khan wrote: > Hi Jakub, > > On 12/08/2017 08:14 AM, Secunia Research wrote: > > Hi Shuah, > > > > Thanks a lot for the quick fixes. > > Thanks for finding them and doing all the leg work in > pin pointing the issues. > > > > > Please, use this

Re: [PATCH 0/4] USB over IP Secuurity fixes

2017-12-08 Thread Shuah Khan
Hi Jakub, On 12/08/2017 08:14 AM, Secunia Research wrote: > Hi Shuah, > > Thanks a lot for the quick fixes. Thanks for finding them and doing all the leg work in pin pointing the issues. > > Please, use this email address: v...@secunia.com > > We have assigned the following CVEs to the

Re: [PATCH 0/4] USB over IP Secuurity fixes

2017-12-08 Thread Shuah Khan
On 12/07/2017 11:25 PM, Greg KH wrote: > On Thu, Dec 07, 2017 at 02:16:46PM -0700, Shuah Khan wrote: >> Jakub Jirasek from Secunia Research at Flexera reported security >> vulnerabilities in the USB over IP driver. This patch series all >> the 4 reported problems. > > Nice! > > These should also

RE: [PATCH 0/4] USB over IP Secuurity fixes

2017-12-08 Thread Secunia Research
Hi Shuah, Thanks a lot for the quick fixes. Please, use this email address: v...@secunia.com We have assigned the following CVEs to the issues: CVE-2017-16911 usbip: prevent vhci_hcd driver from leaking a socket pointer address CVE-2017-16912 usbip: fix stub_rx: get_pipe() to validate endpoint

Re: [PATCH 0/4] USB over IP Secuurity fixes

2017-12-07 Thread Greg KH
On Thu, Dec 07, 2017 at 02:16:46PM -0700, Shuah Khan wrote: > Jakub Jirasek from Secunia Research at Flexera reported security > vulnerabilities in the USB over IP driver. This patch series all > the 4 reported problems. Nice! These should also all go to the stable kernels, right? thanks, greg