Release date: 2010-08-21
Updated on: 2010-09-27
Affected Systems:
Linux kernel 2.6.x
Unaffected system:
Linux kernel 2.6.36-rc4
Description:
--------------------------------------------------------------------------------
Bugtraq id: 42529
CVE (CAN) ID: CVE-2010-3477, CVE-2010-2942
Linux Kernel is the Kernel used by open source Linux.
In the network queue function of Linux Kernel, The tcf_act_rje_dump function under net/sched/act_0000e.c does not properly initialize some structural members, which allows local users to obtain sensitive information from the Kernel memory through the dump operation.
<* Source: Jeff Mahoney (jeffm@suse.com)
Link: http://secunia.com/advisories/41245/
Https://bugzilla.redhat.com/show_bug.cgi? Format = multiple & amp; id = 624903
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Linux
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://git.kernel.org /? P = linux/kernel/git/davem/net-2.6.git; a = commit; h = 0f04cfd098fb81fded74e78ea1b86cc6c6c31e