oss-sec mailing list archives
Re: CVE request: Linux kernel: net: info leak in recvmsg handler msg_name & msg_namelen logic
From: P J P <ppandit () redhat com>
Date: Wed, 11 Dec 2013 11:16:29 +0530 (IST)
+-- On Tue, 10 Dec 2013, Marcus Meissner wrote --+ | CVE-2013-6405 covers parts of that already I think and could be extended? True, that one fixes the individual recvmsg handlers, whereas 'f3d3342602' is one step before that. Small correction: this is an information leak, not memory leak. Content of Kernel memory bytes was inadvertently passed to user space. Thank you. -- Prasad J Pandit / Red Hat Security Response Team
Current thread:
- CVE request: Linux kernel: net: memory leak in recvmsg handler msg_name & msg_namelen logic P J P (Dec 09)
- Re: CVE request: Linux kernel: net: memory leak in recvmsg handler msg_name & msg_namelen logic Marcus Meissner (Dec 10)
- Re: CVE request: Linux kernel: net: info leak in recvmsg handler msg_name & msg_namelen logic P J P (Dec 10)
- Re: CVE request: Linux kernel: net: memory leak in recvmsg handler msg_name & msg_namelen logic P J P (Dec 30)
- Re: CVE request: Linux kernel: net: memory leak in recvmsg handler msg_name & msg_namelen logic Marcus Meissner (Dec 10)