LWN.net Logo

kernel: multiple vulnerabilities

Package(s):kernel CVE #(s):CVE-2013-0913 CVE-2013-0914
Created:March 18, 2013 Updated:March 22, 2013
Description: From the Red Hat bugzilla [1, 2]:

[1] Linux kernel built with Direct Rendering Manager(DRM) i915 driver for the the Direct Rendering Infrastructure(DRI) introduced by XFree86 4.0, is vulnerable to a heap overflow flaw.

An user/program with access to the DRM driver could use this flaw to crash the kernel, resulting in DoS or possibly escalate privileges.

[2] Linux kernel is vulnerable to an information leakage flaw. This occurs when a process calls routine - sigaction() - to access - sa_restorer - parameter. This parameter points to an address that belongs to its parent process' address space.

A user could use this flaw to infer address layout of a process.

Alerts:
Fedora FEDORA-2013-3893 2013-03-17
Fedora FEDORA-2013-3909 2013-03-22
Ubuntu USN-1787-1 2013-04-02
Ubuntu USN-1788-1 2013-04-03

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds