The (1) clcs and (2) emuxki drivers in NetBSD 1.6 through 2.0.2 allow local users to cause a denial of service (kernel crash) by using the set-parameters ioctl on an audio device to change the block size and set the pause state to "unpaused" in the same ioctl, which causes a divide-by-zero error.
Software | From | Fixed in |
---|---|---|
netbsd / netbsd | 1.6 | 1.6.x |
netbsd / netbsd | 1.6.1 | 1.6.1.x |
netbsd / netbsd | 1.6.2 | 1.6.2.x |
netbsd / netbsd | 2.0 | 2.0.x |
netbsd / netbsd | 2.0.1 | 2.0.1.x |
netbsd / netbsd | 2.0.2 | 2.0.2.x |