oss-sec mailing list archives
CVE request: kernel: cpqarray/c: info leak in ida_locked_ioctl()
From: P J P <ppandit () redhat com>
Date: Wed, 5 Jun 2013 12:53:33 +0530 (IST)
HelloA Linux kernel built with the Compaq SMART2(CONFIG_BLK_CPQ_DA) & Compaq Smart Array 5xxx(CONFIG_BLK_CPQ_CISS_DA) support is vulnerable to an information leakage flaw. This could occur while doing an ioctl(2) calls on the block device with command `IDAGETPCIINFO' or `CCISS_PASSTHRU32'.
A user/program could use this flaw to leak kernel memory bytes. Upstream fixes: --------------- -> https://lkml.org/lkml/2013/6/3/131 -> https://lkml.org/lkml/2013/6/3/127 Thank you. -- Prasad J Pandit / Red Hat Security Response Team DB7A 84C5 D3F9 7CD1 B5EB C939 D048 7860 3655 602B
Current thread:
- CVE request: kernel: cpqarray/c: info leak in ida_locked_ioctl() P J P (Jun 05)
- Re: CVE request: kernel: cpqarray/c: info leak in ida_locked_ioctl() P J P (Jun 05)
- Re: CVE request: kernel: cpqarray/c: info leak in ida_locked_ioctl() Kurt Seifried (Jun 05)