Multiple race conditions in the handling of O_DIRECT in Linux kernel prior to version 2.4.22 could cause stale data to be returned from the disk when handling sparse files, or cause incorrect data to be returned when a file is truncated as it is being read, which might allow local users to obtain sensitive data that was originally owned by other users, a different vulnerability than CVE-2003-0018.
References
Link | Resource |
---|---|
http://linux.bkbits.net:8080/linux-2.4/cset@3ef33d95ym_22QH2xwhDMt264M55Fg | Patch Vendor Advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/42942 |
Configurations
Information
Published : 2003-12-30 21:00
Updated : 2017-07-10 18:29
NVD link : CVE-2003-0956
Mitre link : CVE-2003-0956
JSON object : View
CWE
Products Affected
linux
- linux_kernel