oss-sec mailing list archives

Re: CVE request: kernel: arbitrary kernel read in xtensa


From: Josh Bressers <bressers () redhat com>
Date: Wed, 20 Jul 2011 15:52:08 -0400 (EDT)

Please use CVE-2011-2707.

Thanks.

-- 
    JB

----- Original Message -----
Not sure if any distributions support xtensa, but regardless:

Due to a failure to check user pointers passed to a ptrace_setxregs
request, it is possible for a local unprivileged user to read
arbitrary kernel memory [1].

-Dan

[1] http://marc.info/?l=linux-kernel&m=131008344912672&w=2


Current thread: