Release date:
Updated on:
Affected Systems:
Linux kernel <3.12.4
Description:
--------------------------------------------------------------------------------
Bugtraq id: 64743
CVE (CAN) ID: CVE-2013-7266
Linux Kernel is the Kernel of the Linux operating system.
In versions earlier than Linux kernel 3.12.4, drivers/isdn/mISDN/socket. the mISDN_sock_recvmsg function in c does not ensure that some length values are consistent with the relevant data structure. This allows local users to obtain sensitive information about the kernel memory through recvfrom, recvmmsg, and recvmsg system calls.
<* Source: Hannes Frederic Sowa
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Linux
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.kernel.org/
Http://git.kernel.org /? P = linux/kernel/git/torvalds/linux-2.6.git; a = commit; h = f3d3342602f8bcbf37d7c46641cb9bca7618eb1c
CONFIRM: http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.12.4
Https://bugzilla.redhat.com/show_bug.cgi? Id = 1039845
Https://github.com/torvalds/linux/commit/f3d3342602f8bcbf37d7c46641cb9bca7618eb1c