Candidate: CVE-2007-0005 References: http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=059819a41d4331316dd8ddcf977a24ab338f4300 Description: Buffer Overflow in Omnikey CardMan 4040 cmx driver Ubuntu-Description: The Omnikey CardMan 4040 driver (cm4040_cs) did not limit the size of buffers passed to read() and write(). A local attacker could exploit this to execute arbitrary code with kernel privileges. Notes: dannf> Driver wasn't in sarge Bugs: upstream: released (2.6.21, 2.6.20.2) linux-2.6: released (2.6.20-1) [2.6.20.2] 2.6.18-etch-security: released (2.6.18.dfsg.1-12etch1) [bugfix/cm4040-buffer-overflow.patch] 2.6.8-sarge-security: N/A 2.4.27-sarge-security: N/A 2.6.15-dapper-security: released (2.6.15-28.57) 2.6.17-edgy-security: released (2.6.17.1-11.39) [059819a41d4331316dd8ddcf977a24ab338f4300] 2.6.20-feisty-security: N/A