blob: 1048181944824127f2d79174f63a6694dc70ee7d (
plain) (
blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
|
Candidate: CVE-2006-5174
References:
http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=52149ba6b0ddf3e9d965257cc0513193650b3ea8
Description:
The copy_from_user function in the uaccess code in Linux kernel 2.6
before 2.6.19-rc1, when running on s390, does not properly clear a
kernel buffer, which allows local user space programs to read
portions of kernel memory by "appending to a file from a bad
address," which triggers a fault that prevents the unused memory from
being cleared in the kernel buffer.
Ubuntu-Description:
Notes:
jmm> Fix from 2.6.18-3 was reverted, caused problems
Bugs:
upstream: released (2.6.18.1)
linux-2.6: needed
2.6.8-sarge-security: released (2.6.8-16sarge6) [s390-uaccess-memleak.dpatch]
2.4.27-sarge-security: released (2.4.27-10sarge5) [236_s390-uaccess-memleak.diff]
2.6.10-hoary-security: ignored
2.6.12-breezy-security: ignored
2.6.15-dapper-security: ignored
2.6.17-edgy: ignored
|