Vigil@nce - Linux kernel: NULL pointer dereference in the WhiteHEAT driver
October 2015 by Vigil@nce
This bulletin was written by Vigil@nce : http://vigilance.fr/offer
SYNTHESIS OF THE VULNERABILITY
An attacker can force a NULL pointer to be dereferenced in
WhiteHEAT of Linux noyau, in order to trigger a denial of service.
Impacted products: Linux.
Severity: 1/4.
Creation date: 23/09/2015.
DESCRIPTION OF THE VULNERABILITY
The Linux kernel includes a driver for the WhiteHEAT device from
ConnecTech.
However, this module assumes that the number of ports of this
device is constant. When the true number of ports is lower than
expected, the module dereferences a NULL pointer, which leads to a
fatal exception.
An attacker can therefore force a NULL pointer to be dereferenced
in the WhiteHEAT driver of the Linux kernel, in order to trigger a
denial of service.
ACCESS TO THE COMPLETE VIGIL@NCE BULLETIN