Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 211450 (CVE-2008-0598) - Kernel: x86_64 ia32 emulation leaks uninitialized data (CVE-2008-0598)
Summary: Kernel: x86_64 ia32 emulation leaks uninitialized data (CVE-2008-0598)
Status: RESOLVED FIXED
Alias: CVE-2008-0598
Product: Gentoo Security
Classification: Unclassified
Component: Kernel (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: http://securitytracker.com/alerts/200...
Whiteboard: [linux <2.6.10] [linux >=2.6.18 <2.6.24]
Keywords:
Depends on:
Blocks:
 
Reported: 2008-02-25 21:04 UTC by Sune Kloppenborg Jeppesen (RETIRED)
Modified: 2013-09-05 03:36 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2008-02-25 21:04:10 UTC
Tavis Ormandy reports that programs can leak data from other processes.
Comment 1 Pierre-Yves Rofes (RETIRED) gentoo-dev 2008-09-19 21:05:53 UTC
Public too.
Comment 2 Bjoern Tropf (RETIRED) gentoo-dev 2009-07-14 07:38:32 UTC
Whiteboard guessed from CVE description since i am missing detailed information.
An exploit (to check if a kernel is affected or not) is provided by Marcus Meissner:
https://bugzilla.redhat.com/show_bug.cgi?id=433938#c38
Comment 3 Robert Buchholz (RETIRED) gentoo-dev 2009-07-14 10:00:24 UTC
This is the fix:

commit 64649a58919e66ec21792dbb6c48cb3da22cbd7f
Author: Nick Piggin <npiggin@suse.de>
Date:   Tue Oct 16 01:24:56 2007 -0700

    mm: trim more holes