Multiple integer signedness errors in the TIPC implementation in the Linux kernel before 2.6.36.2 allow local users to gain privileges via a crafted sendmsg call that triggers a heap-based buffer overflow, related to the tipc_msg_build function in net/tipc/msg.c and the verify_iovec function in net/core/iovec.c.
| Software | From | Fixed in |
|---|---|---|
| linux / linux_kernel | - | 2.6.36.2 |
| debian / debian_linux | 5.0 | 5.0.x |