PT-2012-1566 · Linux · Linux Kernel

Dan Rosenberg

·

Published

2012-05-24

·

Updated

2023-02-13

·

CVE-2011-2707

CVSS v2.0

3.6

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:P
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 3.1
Description The issue allows local users to obtain sensitive information from kernel memory locations. This is due to the ptrace setxregs function in arch/xtensa/kernel/ptrace.c not validating user-space pointers, enabling users to craft a PTRACE SETXTREGS request to access sensitive information.
Recommendations For Linux kernel versions prior to 3.1, update to version 3.1 or later to resolve the issue.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2011-2707

Affected Products

Linux Kernel