LWN.net Logo

kernel: multiple vulnerabilities

Package(s):kernel CVE #(s):CVE-2012-5374 CVE-2013-0160
Created:March 5, 2013 Updated:March 6, 2013
Description: From the CVE entries:

The CRC32C feature in the Btrfs implementation in the Linux kernel before 3.8-rc1 allows local users to cause a denial of service (extended runtime of kernel code) by creating many different files whose names are associated with the same CRC32C hash value. (CVE-2012-5374)

The Linux kernel through 3.7.9 allows local users to obtain sensitive information about keystroke timing by using the inotify API on the /dev/ptmx device. (CVE-2013-0160)

Alerts:
openSUSE openSUSE-SU-2013:0395-1 2013-03-05
openSUSE openSUSE-SU-2013:0396-1 2013-03-05

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds