Linux Kernel ETHTOOL_GRXCLSRLALL local information leakage Vulnerability
Release date:
Updated on:
Affected Systems:
Linux kernel 2.6.27-git3-2.6.35
Description:
--------------------------------------------------------------------------------
Bugtraq id: 44427
Cve id: CVE-2010-3861
Linux Kernel is the Kernel used by open source Linux.
Linux Kernels has a vulnerability in implementation. Attackers can exploit this vulnerability to obtain sensitive information.
This vulnerability is caused by calling ETHTOOL_GRXCLSRLALL with a large rule_cnt to allocate the Kernel Heap without clearing it.
<* Source: Kees Cook (kees@Ubuntu.com)
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Linux
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.kernel.org/