PT-2014-2863 · Linux · Linux Kernel

Jonathan Salwan

·

Published

2014-02-03

·

Updated

2014-02-07

·

CVE-2013-4739

CVSS v2.0

4.9

Medium

VectorAV:L/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Linux kernel versions 3.x
Description The issue allows attackers to obtain sensitive information from kernel stack memory. This can be achieved through a crafted MSM MCR IOCTL EVT GET ioctl call related to drivers/media/platform/msm/camera v1/mercury/msm mercury sync.c, or a crafted MSM JPEG IOCTL EVT GET ioctl call related to drivers/media/platform/msm/camera v2/jpeg 10/msm jpeg sync.c.
Recommendations For Linux kernel version 3.x, consider restricting access to the MSM MCR IOCTL EVT GET and MSM JPEG IOCTL EVT GET ioctl calls until a patch is available. As a temporary workaround, disabling the msm mercury sync.c and msm jpeg sync.c functions may help minimize the risk of exploitation.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-4739

Affected Products

Linux Kernel