First published: Tue May 28 2013(Updated: )
A flaw was found in the way Linux kernel's iSCSI target processed large keys. If a key was larger than 64 bytes, as checked by iscsi_check_key(), the error response packet, generated by iscsi_add_notunderstood_response(), would still attempt to copy the entire key into the packet, overflowing the structure on the heap. A remote attacker could use this flaw to escalate their privileges on the system. Acknowledgements: Red Hat would like to thank Kees Cook for reporting this issue.
Credit: chrome-cve-admin@google.com cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Linux kernel | >=3.1<3.2.47 | |
Linux Linux kernel | >=3.3<3.4.48 | |
Linux Linux kernel | >=3.5<3.9.5 | |
debian/linux | 5.10.223-1 5.10.226-1 6.1.115-1 6.1.119-1 6.11.10-1 6.12.5-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.