PT-2009-5205 · Linux+1 · Linux Kernel+1
Eugene Teo
+1
·
Published
2009-08-18
·
Updated
2018-10-10
·
CVE-2009-2847
CVSS v2.0
4.9
Medium
| Vector | AV:L/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions 2.4 through 2.4.37
Linux kernel versions 2.6 before 2.6.31-rc5
Description
The issue allows local users to obtain sensitive information from the kernel stack via the sigaltstack function due to the do sigaltstack function in kernel/signal.c not clearing certain padding bytes from a structure when running on 64-bit systems.
Recommendations
For Linux kernel versions 2.4 through 2.4.37, consider upgrading to a version outside of this range to mitigate the risk.
For Linux kernel versions 2.6 before 2.6.31-rc5, update to version 2.6.31-rc5 or later to resolve the issue.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel
Red Hat