Linux Kernel Real-time Clock Routines May Leak Kernel Data to User Applications
|
|
SecurityTracker Alert ID: 1008594
|
|
SecurityTracker URL: http://securitytracker.com/id?1008594
|
|
CVE Reference: CVE-2003-0984
(Links to External Site)
|
Updated: Jul 6 2008
|
Original Entry Date: Jan 5 2004
|
Impact: Disclosure of authentication information, Disclosure of system information, Disclosure of user information
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Version(s): 2.4.23 and prior 2.4.x kernels
|
Description: A vulnerability was reported in the Linux 2.4 kernel in the real-time clock routines. A local user may be able to view leaked kernel data.
In December 2003, it was reported that real time clock routines in the Linux kernel do not properly initialize memory structures. As a result, a local user may be able to access the routines to view kernel stack data.
|
Impact: A local user may be able to view some kernel data.
|
Solution: Fixes are reportedly available (or pending) for various Linux kernel distributions. As the distributors release their fixes, separate Alerts will be issued [see the Message History].
|
Vendor URL: www.kernel.org/ (Links to External Site)
|
Cause: State error
|
Underlying OS: Linux (Caldera/SCO), Linux (Conectiva), Linux (Debian), Linux (EnGarde), Linux (Gentoo), Linux (HP Secure OS), Linux (Immunix), Linux (Mandriva/Mandrake), Linux (Progeny Debian), Linux (Red Hat Enterprise), Linux (Red Hat Fedora), Linux (Red Hat Linux), Linux (SGI), Linux (Slackware), Linux (Sun), Linux (SuSE), Linux (Trustix), Linux (Turbo Linux), Linux (Xandros)
|
|
Message History:
This archive entry has one or more follow-up message(s) listed below.
|
Source Message Contents
|
Date: Tue, 23 Dec 2003 14:18:02 -0500
Subject: CAN-2003-0984
|
In SuSE-SA:2003:049 (http://www.suse.com/de/security/2003_049_kernel.html), SuSE reported
a Linux 2.4 kernel vulnerability.
> This update also fixes several other security issues in the kernel
> - when reading the RTC, don't leak kernel stack data to user space
The CVE CAN-2003-0984 entry says:
> Real time clock (RTC) routines in Linux kernel 2.4.23 and earlier do not properly
> initialize their structures, which could leak kernel data to user space.
|
|