CVE

Id
49406  
CVE No.
CVE-2011-1494  
Status
Candidate  
Description
Integer overflow in the _ctl_do_mpt_command function in drivers/scsi/mpt2sas/mpt2sas_ctl.c in the Linux kernel 2.6.38 and earlier might allow local users to gain privileges or cause a denial of service (memory corruption) via an ioctl call specifying a crafted value that triggers a heap-based buffer overflow.  
Phase
Assigned (20110321)  
Votes
None (candidate not yet proposed)  
Comments