Release date: 2010-09-08
Updated on: 2010-09-09
Affected Systems:
Linux kernel 2.6.x
Description:
--------------------------------------------------------------------------------
Cve id: CVE-2010-3078
Linux Kernel is the Kernel used by open source Linux.
The xfs_ioc_fsgetxattr () function in the fs/xfs/linux-2.6/xfs_ioctl.c file of Linux Kernel copies all members of some structures to the user space without correctly initializing them, local users can leak the kernel stack memory by sending XFS_IOC_FSGETXATTR IOCTL requests.
<* Source: Dan Rosenberg
Link: http://secunia.com/advisories/41284/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Linux
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.linux.sgi.com/cgi-bin/mesg.cgi? A = xfs-masters & I = AANLkTi % 3DHdtMVJk7rCf89zirUcyn-5qc % 2B50soVt % 3D7dE6t % 40mail.gmail.com