New 4-series kernel commits

For discussions about security.
Post Reply
User avatar
8Geee
Posts: 376
Joined: Wed Jul 29, 2020 10:52 pm
Location: N.E. USA
Has thanked: 17 times
Been thanked: 54 times

New 4-series kernel commits

Post by 8Geee »

Just checked in at kernel org...

All newest 4-series have some important commits, two of which concern check/handling the length of the crypto key to insure proper length. Advancement in the crypto-process continued without completion/verification of the key-length checks. Rouge/undefined behavior is possible w/o these patches.

Bluetooth has a series of patches designed to eliminate the "E0(zero)" value in a BT4.x device. The new 5-series specifications do not have this limitation, so it must be added back when a BT4.x device is called. NOTE that "down the line" this also affects security. E0 is forbidden in BT4.x devices. Without the patches rouge/undefined behavior can exist.

Regards
8Geee

Money talks... no, it shouts, so that it doesn't have to hear common sense.

Post Reply

Return to “Security”