CVE-2013-3222: Infoleak
Last updated 24 July 2024
Other sources
The vccrecvmsg function in net/atm/common.c in the Linux kernel before 3.9-rc7 does not initialize a certain length variable, which allows local users to obtain sensitive information from kernel stack memory via a crafted recvmsg or recvfrom system call.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-3222?
CVE-2013-3222 is considered to have a moderate severity level due to potential local information disclosure.
How do I fix CVE-2013-3222?
To fix CVE-2013-3222, upgrade your Linux kernel to version 3.9-rc7 or later.
What systems are affected by CVE-2013-3222?
CVE-2013-3222 affects Linux kernel versions prior to 3.9-rc7, specifically from 3.9-rc1 up to 3.9-rc6.
What type of exploit does CVE-2013-3222 allow?
CVE-2013-3222 allows local users to gain access to sensitive information from kernel stack memory.
How can I determine if my system is vulnerable to CVE-2013-3222?
You can determine if your system is vulnerable by checking the version of the Linux kernel installed and comparing it to the affected versions of CVE-2013-3222.