arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel before 3.12 does not have an exit handler for the INVEPT instruction, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application.
A flaw was found in the way netctlpermissions() function in the Linux kernel checked permissions.
As a result, an unprivileged local user could potentially use this flaw to access files in /proc/sys/net in a way that he would otherwise be unable to.
Introduced by:
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=cff109768b2d9c03095848f4cd4b0754117262aa
Fixed by:
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=2433c8f094a008895e66f25bd1773cdb01c91d01
Acknowledgements:
This issue was discovered by Miroslav Vadkerti of Red Hat.
Last updated 24 July 2024
Last updated 24 July 2024
Last updated 24 July 2024
The l2tpip6getname function in net/l2tp/l2tpip6.c in the Linux kernel before 3.6 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel stack memory via a crafted application.
Last updated 24 July 2024
Last updated 24 July 2024
Last updated 24 July 2024
Last updated 24 July 2024
Last updated 24 July 2024
Last updated 24 July 2024
Last updated 24 July 2024
Last updated 24 July 2024
Last updated 24 July 2024
Last updated 24 July 2024
Last updated 24 July 2024
Last updated 24 July 2024
Last updated 24 July 2024
A memory disclosure flaw has been found in the way binfmtscript loadscript() function handled excessive recursions. An unprivileged local user could use this flaw to leak kernel memory.
References: - http://www.halfdog.net/Security/2012/LinuxKernelBinfmtScriptStackDataDisclosure/ - https://lkml.org/lkml/2012/8/18/75
Proposed upstream fix: - https://lkml.org/lkml/2012/9/23/29