Описание
The actions implementation in the network queueing functionality in the Linux kernel before 2.6.36-rc2 does not properly initialize certain structure members when performing dump operations, which allows local users to obtain potentially sensitive information from kernel memory via vectors related to (1) the tcf_gact_dump function in net/sched/act_gact.c, (2) the tcf_mirred_dump function in net/sched/act_mirred.c, (3) the tcf_nat_dump function in net/sched/act_nat.c, (4) the tcf_simp_dump function in net/sched/act_simple.c, and (5) the tcf_skbedit_dump function in net/sched/act_skbedit.c.
Релиз | Статус | Примечание |
---|---|---|
dapper | DNE | |
devel | not-affected | |
hardy | released | 2.6.24-28.80 |
jaunty | released | 2.6.28-19.66 |
karmic | released | 2.6.31-22.67 |
lucid | released | 2.6.32-25.45 |
maverick | not-affected | |
upstream | released | 2.6.36~rc2 |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
dapper | DNE | |
devel | DNE | |
hardy | DNE | |
karmic | released | 2.6.31-307.21 |
lucid | released | 2.6.32-309.18 |
maverick | ignored | end of life |
upstream | released | 2.6.36~rc2 |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
dapper | DNE | |
devel | DNE | |
hardy | DNE | |
karmic | released | 2.6.31-112.30 |
lucid | released | 2.6.31-608.22 |
maverick | DNE | |
upstream | released | 2.6.36~rc2 |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
dapper | DNE | |
devel | DNE | |
hardy | DNE | |
karmic | DNE | |
lucid | released | 2.6.35-25.44~lucid1 |
maverick | DNE | |
upstream | released | 2.6.36~rc2 |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
dapper | DNE | |
devel | DNE | |
hardy | DNE | |
karmic | ignored | end of life |
lucid | released | 2.6.32-216.33 |
maverick | released | 2.6.32-416.33 |
upstream | released | 2.6.36~rc2 |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
dapper | released | 2.6.15-55.89 |
devel | DNE | |
hardy | DNE | |
jaunty | DNE | |
karmic | DNE | |
lucid | DNE | |
maverick | DNE | |
upstream | released | 2.6.36~rc2 |
Показывать по
EPSS
2.1 Low
CVSS2
5.5 Medium
CVSS3
Связанные уязвимости
The actions implementation in the network queueing functionality in the Linux kernel before 2.6.36-rc2 does not properly initialize certain structure members when performing dump operations, which allows local users to obtain potentially sensitive information from kernel memory via vectors related to (1) the tcf_gact_dump function in net/sched/act_gact.c, (2) the tcf_mirred_dump function in net/sched/act_mirred.c, (3) the tcf_nat_dump function in net/sched/act_nat.c, (4) the tcf_simp_dump function in net/sched/act_simple.c, and (5) the tcf_skbedit_dump function in net/sched/act_skbedit.c.
The actions implementation in the network queueing functionality in the Linux kernel before 2.6.36-rc2 does not properly initialize certain structure members when performing dump operations, which allows local users to obtain potentially sensitive information from kernel memory via vectors related to (1) the tcf_gact_dump function in net/sched/act_gact.c, (2) the tcf_mirred_dump function in net/sched/act_mirred.c, (3) the tcf_nat_dump function in net/sched/act_nat.c, (4) the tcf_simp_dump function in net/sched/act_simple.c, and (5) the tcf_skbedit_dump function in net/sched/act_skbedit.c.
The actions implementation in the network queueing functionality in th ...
The actions implementation in the network queueing functionality in the Linux kernel before 2.6.36-rc2 does not properly initialize certain structure members when performing dump operations, which allows local users to obtain potentially sensitive information from kernel memory via vectors related to (1) the tcf_gact_dump function in net/sched/act_gact.c, (2) the tcf_mirred_dump function in net/sched/act_mirred.c, (3) the tcf_nat_dump function in net/sched/act_nat.c, (4) the tcf_simp_dump function in net/sched/act_simple.c, and (5) the tcf_skbedit_dump function in net/sched/act_skbedit.c.
ELSA-2010-2008: Unbreakable enterprise kernel security update (IMPORTANT)
EPSS
2.1 Low
CVSS2
5.5 Medium
CVSS3