CVE-2011-0463: Input Validation
Last updated 24 July 2024
Other sources
The ocfs2preparepageforwrite function in fs/ocfs2/aops.c in the Oracle Cluster File System 2 (OCFS2) subsystem in the Linux kernel before 2.6.39-rc1 does not properly handle holes that cross page boundaries, which allows local users to obtain potentially sensitive information from uninitialized disk locations by reading a file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2011-0463?
CVE-2011-0463 is classified as a medium severity vulnerability.
How do I fix CVE-2011-0463?
To address CVE-2011-0463, upgrade your Linux kernel to version 2.6.39-rc1 or later.
Who is affected by CVE-2011-0463?
CVE-2011-0463 affects local users on systems running affected versions of the OCFS2 subsystem in the Linux kernel.
What types of systems are vulnerable to CVE-2011-0463?
Vulnerable systems include those running Linux kernel versions prior to 2.6.39-rc1 and specific distributions like Ubuntu 8.04.
What kind of information can be compromised by CVE-2011-0463?
CVE-2011-0463 potentially allows local users to obtain sensitive information through improper handling of memory pages.