PT-2014-2863 · Linux · Linux Kernel
Jonathan Salwan
·
Published
2014-02-03
·
Updated
2014-02-07
·
CVE-2013-4739
CVSS v2.0
4.9
Medium
| Vector | AV:L/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions 3.x
Description
The issue allows attackers to obtain sensitive information from kernel stack memory. This can be achieved through a crafted
MSM MCR IOCTL EVT GET ioctl call related to drivers/media/platform/msm/camera v1/mercury/msm mercury sync.c, or a crafted MSM JPEG IOCTL EVT GET ioctl call related to drivers/media/platform/msm/camera v2/jpeg 10/msm jpeg sync.c.Recommendations
For Linux kernel version 3.x, consider restricting access to the
MSM MCR IOCTL EVT GET and MSM JPEG IOCTL EVT GET ioctl calls until a patch is available. As a temporary workaround, disabling the msm mercury sync.c and msm jpeg sync.c functions may help minimize the risk of exploitation.Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linux Kernel