First published: Wed Feb 19 2014(Updated: )
It was found that cached page was not up-to-date in certain cases when we were extending write to cover the full page and thus contained uninitalized data. A local user with write access to file on nfs share could use this flaw to leak kernel memory. Please note that apart from having security consequences (data leak), this bug is also a data corruptor. Introduced by: <a href="https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=c7559663">https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=c7559663</a> Upstream fix: <a href="https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=263b4509">https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=263b4509</a>
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Linux kernel | <3.13.3 | |
Canonical Ubuntu Linux | =12.04 | |
Canonical Ubuntu Linux | =13.10 | |
debian/linux | 5.10.223-1 5.10.226-1 6.1.115-1 6.1.119-1 6.11.10-1 6.12.5-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.