LWN.net Logo

kernel: information leak

Package(s):kernel CVE #(s):CVE-2010-0003
Created:January 25, 2010 Updated:March 23, 2010
Description:

From the Red Hat bugzilla entry:

When print-fatal-signals is enabled it's possible to dump any memory reachable by the kernel to the log by simply jumping to that address from user space.

Or crash the system if there's some hardware with read side effects.

The fatal signals handler will dump 16 bytes at the execution address, which is fully controlled by ring 3.

Alerts:
Red Hat RHSA-2010:0161-01 2010-03-23
CentOS CESA-2010:0147 2010-03-18
CentOS CESA-2010:0146 2010-03-17
Red Hat RHSA-2010:0147-01 2010-03-16
Red Hat RHSA-2010:0146-01 2010-03-16
Ubuntu USN-894-1 2010-02-05
Fedora FEDORA-2010-0919 2010-01-22
Debian DSA-1996-1 2010-02-12
SuSE SUSE-SA:2010:010 2010-02-08
SuSE SUSE-SA:2010:012 2010-02-15
SuSE SUSE-SA:2010:014 2010-03-03
Debian DSA-2004-1 2010-02-27

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds