Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 493012 (CVE-2013-6405) - Kernel: net: leakage of uninitialized memory to user-space via recv syscalls (CVE-2013-6405)
Summary: Kernel: net: leakage of uninitialized memory to user-space via recv syscalls ...
Status: RESOLVED FIXED
Alias: CVE-2013-6405
Product: Gentoo Security
Classification: Unclassified
Component: Kernel (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Kernel Security
URL: https://bugzilla.redhat.com/show_bug....
Whiteboard: [linux < 3.13_rc1]
Keywords:
Depends on:
Blocks:
 
Reported: 2013-12-01 09:13 UTC by Agostino Sarubbo
Modified: 2022-03-25 16:44 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2013-12-01 09:13:50 UTC
From ${URL} :

Linux kernel built with the networking support(CONFIG_NET), is vulnerable to a
memory leakage flaw. It occurs while doing the recvmsg(2), recvfrom(2),
recvmmsg(2) socket calls.

A user/program could use this flaw to leak kernel memory bytes.

Upstream fix:
-------------
 -> 
https://git.kernel.org/cgit/linux/kernel/git/davem/net.git/commit/?id=bceaa90240b6019ed73b49965eac7d167610be69

 -> 
https://git.kernel.org/cgit/linux/kernel/git/davem/net.git/commit/?id=85fbaa75037d0b6b786ff18658ddf0b4014ce2a4
Comment 1 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-03-25 16:44:11 UTC
Fixes in 3.12.4