Release date:
Updated on:
Affected Systems:
Linux kernel <3.12.4
Description:
--------------------------------------------------------------------------------
Bugtraq id: 64747
CVE (CAN) ID: CVE-2013-7281
Linux Kernel is the Kernel of the Linux operating system.
In versions earlier than Linux kernel 3.12.4, net/ieee802154/dgram. the function dgram_recvmsg in c does not ensure that some length values are updated when related data results are initialized. This allows local users to call the function through the recvfrom, recvmmsg, and recvmsg systems, attackers can obtain sensitive information about the kernel memory.
<* Source: mpb
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Linux
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.kernel.org/
Http://git.kernel.org /? P = linux/kernel/git/torvalds/linux-2.6.git; a = commit; h = f3d3342602f8bcbf37d7c46641cb9bca7618eb1c
CONFIRM: http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.12.4
Https://bugzilla.redhat.com/show_bug.cgi? Id = 1039845
Https://github.com/torvalds/linux/commit/f3d3342602f8bcbf37d7c46641cb9bca7618eb1c