Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2012-3430

Опубликовано: 23 июл. 2012
Источник: redhat
CVSS2: 2.1

Описание

The rds_recvmsg function in net/rds/recv.c in the Linux kernel before 3.0.44 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via a (1) recvfrom or (2) recvmsg system call on an RDS socket.

Отчет

The Red Hat Security Response Team has rated this issue as having low security impact. A future kernel updates may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4kernelWill not fix
Red Hat Enterprise Linux 5kernelFixedRHSA-2012:132302.10.2012
Red Hat Enterprise Linux 6kernelFixedRHSA-2012:130425.09.2012
Red Hat Enterprise MRG 2kernel-rtFixedRHSA-2012:149104.12.2012

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=820039kernel: recv{from,msg}() on an rds socket can leak kernel memory

2.1 Low

CVSS2

Связанные уязвимости

ubuntu
около 13 лет назад

The rds_recvmsg function in net/rds/recv.c in the Linux kernel before 3.0.44 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via a (1) recvfrom or (2) recvmsg system call on an RDS socket.

nvd
около 13 лет назад

The rds_recvmsg function in net/rds/recv.c in the Linux kernel before 3.0.44 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via a (1) recvfrom or (2) recvmsg system call on an RDS socket.

debian
около 13 лет назад

The rds_recvmsg function in net/rds/recv.c in the Linux kernel before ...

github
больше 3 лет назад

The rds_recvmsg function in net/rds/recv.c in the Linux kernel before 3.0.44 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via a (1) recvfrom or (2) recvmsg system call on an RDS socket.

oracle-oval
около 13 лет назад

ELSA-2012-2037: Unbreakable Enterprise kernel Security update (IMPORTANT)

2.1 Low

CVSS2