Candidate: CVE-2005-3055 References: URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3055 Final-Decision: Interim-Decision: Modified: Proposed: Assigned: 20050926 Category: SF MLIST:[linux-kernel] 20050925 [BUG/PATCH/RFC] Oops while completing async USB via usbdevio URL:http://marc.theaimsgroup.com/?l=linux-kernel&m=112766129313883 Description: Linux kernel 2.6.8 to 2.6.14-rc2 allows local users to cause a denial of service (kernel OOPS) via a userspace process that issues a USB Request Block (URB) to a USB device and terminates before the URB is finished, which leads to a stale pointer reference. Notes: horms> http://lkml.org/lkml/mbox/2005/10/11/90 horms> http://lkml.org/lkml/2005/10/11/90 horms> http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=330287;msg=21 Bugs: 330287, 332587 upstream: released (2.6.14-rc4) linux-2.6: released (2.6.14-1) 2.6.8-sarge-security: released (2.6.8-16sarge2) 2.4.27-sid/sarge: N/A 2.4.27-sarge-security: N/A 2.4.19-woody-security: 2.4.18-woody-security: 2.4.17-woody-security: 2.4.16-woody-security: 2.4.17-woody-security-hppa: 2.4.17-woody-security-ia64: 2.4.18-woody-security-hppa: