Release date:
Updated on:
Affected Systems:
Linux kernel <= 3.9.4
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2013-2851
Linux Kernel is the Kernel of the Linux operating system.
Block/genhd versions earlier than Linux kernel 3.9.4. the register_disk function in c has a format string vulnerability, which allows local users to access and write Format String indicators to/sys/module/md_mod/parameters/new_array using the root user, attackers can exploit this vulnerability to obtain permissions.
<* Source: Kees Cook (kees@ubuntu.com)
Link: https://bugzilla.redhat.com/show_bug.cgi? Id = 969515
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Linux
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.kernel.org/
Http://git.kernel.org/cgit/linux/kernel/git/linville/wireless.git/commit? Id = 9538cbaab6e8b8046039b4b2eb6c9d614dc782bd