LWN.net Logo

kernel: information leak

Package(s):linux CVE #(s):CVE-2013-3226
Created:May 24, 2013 Updated:May 30, 2013
Description: From the CVE entry:

The sco_sock_recvmsg function in net/bluetooth/sco.c in the Linux kernel before 3.9-rc7 does not initialize a certain length variable, which allows local users to obtain sensitive information from kernel stack memory via a crafted recvmsg or recvfrom system call.

Alerts:
Ubuntu USN-1837-1 2013-05-24

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds