The iowarrior_write function in drivers/usb/misc/iowarrior.c in the Linux kernel before 2.6.37 does not properly allocate memory, which might allow local users to trigger a heap-based buffer overflow, and consequently cause a denial of service or gain privileges, via a long report.
| Product | Vendor | Version |
|---|---|---|
| n/a | n/a | < a9aaadcb0a6ce0c19616c46525112bc947c6f2b1 |