Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2012-3430

Overview

Vulnerability Score 2.1 2.1
CVE Id CVE-2012-3430
Last Modified 18 Apr 2013 11:23:26
Published 03 Oct 2012 07:02:56
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact NONE NONE
Availability Impact NONE NONE
Access Vector LOCAL
Access Complexity LOW
Authentication NONE

CVE-2012-3430

Summary

The rds_recvmsg function in net/rds/recv.c in the Linux kernel before 3.0.44 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via a (1) recvfrom or (2) recvmsg system call on an RDS socket.

Vulnerable Systems

Operating System

  • Linux Kernel 3.0.1

  • Linux Kernel 3.0.10

  • Linux Kernel 3.0.11

  • Linux Kernel 3.0.12

  • Linux Kernel 3.0.13

  • Linux Kernel 3.0.14

  • Linux Kernel 3.0.15

  • Linux Kernel 3.0.16

  • Linux Kernel 3.0.17

  • Linux Kernel 3.0.18

  • Linux Kernel 3.0.19

  • Linux Kernel 3.0.2

  • Linux Kernel 3.0.20

  • Linux Kernel 3.0.21

  • Linux Kernel 3.0.22

  • Linux Kernel 3.0.23

  • Linux Kernel 3.0.24

  • Linux Kernel 3.0.25

  • Linux Kernel 3.0.26

  • Linux Kernel 3.0.27

  • Linux Kernel 3.0.28

  • Linux Kernel 3.0.29

  • Linux Kernel 3.0.3

  • Linux Kernel 3.0.30

  • Linux Kernel 3.0.31

  • Linux Kernel 3.0.32

  • Linux Kernel 3.0.33

  • Linux Kernel 3.0.34

  • Linux Kernel 3.0.35

  • Linux Kernel 3.0.36

  • Linux Kernel 3.0.37

  • Linux Kernel 3.0.38

  • Linux Kernel 3.0.39

  • Linux Kernel 3.0.4

  • Linux Kernel 3.0.40

  • Linux Kernel 3.0.41

  • Linux Kernel 3.0.42

  • Linux Kernel 3.0.43

  • Linux Kernel 3.0.5

  • Linux Kernel 3.0.6

  • Linux Kernel 3.0.7

  • Linux Kernel 3.0.8

  • Linux Kernel 3.0.9


References

CONFIRM - http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=06b6a1cf6e776426766298d055bb3991957d90a7

CONFIRM - https://github.com/torvalds/linux/commit/06b6a1cf6e776426766298d055bb3991957d90a7

CONFIRM - https://bugzilla.redhat.com/show_bug.cgi?id=820039

MLIST - [oss-security] 20120726 Re: CVE Request -- kernel: recv{from,msg}() on an rds socket can leak kernel memory

CONFIRM - http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.0.44

UBUNTU - USN-1580-1

UBUNTU - USN-1579-1

UBUNTU - USN-1572-1

UBUNTU - USN-1568-1

UBUNTU - USN-1567-1

SUSE - SUSE-SU-2012:1679

UBUNTU - USN-1578-1

UBUNTU - USN-1577-1

UBUNTU - USN-1575-1

REDHAT - RHSA-2012:1323

SECUNIA - 50811

SECUNIA - 50732

SECUNIA - 50633

Related Patches

Red Hat 2012:1323-01 RHSA Important: kernel security and bug fix update for RHEL 5 x86

Novell SUSE 2012:7123 kernel security update for SLE 11 SP2 i586

Novell SUSE 2012:7127 kernel security update for SLE 11 SP2 x86_64

Novell SUSE 2012:8386 ofed security update for SLES 10 SP4 i586

Novell SUSE 2012:8386 ofed security update for SLES 10 SP4 x86_64


Last Updated: 27 May 2016 11:00:50