PT-2013-3614 · Linux+1 · Linux Kernel+1
Jonathan Salwan
·
Published
2013-11-12
·
Updated
2014-02-07
·
CVE-2013-2239
CVSS v2.0
4.7
Medium
| Vector | AV:L/AC:M/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenVZ modification for the Linux kernel version 2.6.32, specifically vzkernel before 042stab080.2
Description
The issue allows local users to obtain sensitive information from kernel stack memory. This can be achieved via a crafted ploop driver ioctl call, related to the
ploop getdevice ioc function in drivers/block/ploop/dev.c, or a crafted quotactl system call, related to the compat quotactl function in fs/quota/quota.c.Recommendations
For vzkernel before 042stab080.2, update to version 042stab080.2 or later to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linux Kernel
Openvz