Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 385945 (CVE-2011-2898)

Summary: Kernel: linux >= 2.6.39.1 "packet_recvmsg()" and "tpacket_rcv()" functions (net/packet/af_packet.c) do not properly initialise (CVE-2011-{2208,2209,2210,2211,2517,2898})
Product: Gentoo Security Reporter: Michael Harrison <n0idx80>
Component: KernelAssignee: Gentoo Kernel Security <security-kernel>
Status: RESOLVED FIXED    
Severity: trivial CC: kernel
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: http://secunia.com/advisories/44754/
Whiteboard: [linux >= 2.6.39.1]
Package list:
Runtime testing required: ---

Description Michael Harrison 2011-10-06 20:34:29 UTC
The "packet_recvmsg()" and "tpacket_rcv()" functions (net/packet/af_packet.c) do not properly initialise a structure before copying it to userspace, which can be exploited to disclose kernel memory.
Comment 2 Aaron Bauman (RETIRED) gentoo-dev 2018-04-04 17:40:58 UTC
There are no longer any 2.x kernels available in the repository with the exception of sys-kernel/xbox-sources which is unsupported by security.