PT-2011-2913 · Linux+1 · Linux Kernel+1
Peter Huewe
·
Published
2011-11-22
·
Updated
2012-03-19
·
CVE-2011-1162
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Linux kernel version 2.6
Description
The issue is related to the
tpm read function in the Linux kernel, which does not properly clear memory. This might allow local users to read the results of the previous TPM command.Recommendations
For Linux kernel version 2.6, consider applying a patch that properly clears memory after the
tpm read function is executed, or update to a newer version that includes this fix. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linux Kernel
Red Hat