The Linux kernel before 3.12.4 updates certain length values before ensuring that associated data structures have been initialized, which allows local users to obtain sensitive information from kernel stack memory via a (1) recvfrom, (2) recvmmsg, or (3) recvmsg system call, related to net/ipv4/ping.c, net/ipv4/raw.c, net/ipv4/udp.c, net/ipv6/raw.c, and net/ipv6/udp.c.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2014-01-06 08:55
Updated : 2017-12-15 18:29
NVD link : CVE-2013-7263
Mitre link : CVE-2013-7263
JSON object : View
CWE
CWE-20
Improper Input Validation
Products Affected
linux
- linux_kernel