漏洞信息详情
Linux Kernel 程序'drivers/usb/core/devio.c'本地信息泄露漏洞
漏洞简介
Linux kernel是美国Linux基金会发布的开源操作系统Linux所使用的内核。NFSv4 implementation是其中的一个分布式文件系统协议。
Linux Kernel 程序\'\'drivers/usb/core/devio.c\'\'函数processcompl_compat存在本地信息泄露漏洞。在出现设备通讯失败的时候(如USB超时),Linux Kernel的drivers/usb/core/devio.c文件中的processcompl()和processcompl_compat()函数将transfer缓冲区未经修改的返回给了用户空间进程,其中可能包含有最近释放的内核数据。
漏洞公告
目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载:
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=d4a4683ca054ed9917dfc9e3ff0f7ecf74ad90d6
参考网址
来源: MLIST
名称: [oss-security] 20100217 additional memory leak in USB userspace handling
链接:http://www.openwall.com/lists/oss-security/2010/02/17/2
来源: MLIST
名称: [linux-kernel] 20100221 [80/93] USB: usbfs: properly clean up the as structure on error paths
链接:http://lwn.net/Articles/375350/
来源: MLIST
名称: [oss-security] 20100219 Re: CVE request: kernel information leak via userspace USB interface
链接:http://www.openwall.com/lists/oss-security/2010/02/19/1
来源: MLIST
名称: [oss-security] 20100218 Re: CVE request: kernel information leak via userspace USB interface
链接:http://www.openwall.com/lists/oss-security/2010/02/18/7
来源: MLIST
名称: [oss-security] 20100219 Re: additional memory leak in USB userspace handling
链接:http://www.openwall.com/lists/oss-security/2010/02/18/4
来源: MLIST
名称: [oss-security] 20100217 CVE request: kernel information leak via userspace USB interface
链接:http://www.openwall.com/lists/oss-security/2010/02/17/1
来源: MLIST
名称: [linux-kernel] 20100330 [48/89] USB: usbfs: properly clean up the as structure on error paths
链接:http://lkml.org/lkml/2010/3/30/759
来源:NSFOCUS 名称:14736 链接:http://www.nsfocus.net/vulndb/14736
受影响实体
- Linux Linux_kernel:2.6.32<!--2000-1-1-->
- Linux Linux_kernel:2.6.30:Rc7-Git6<!--2000-1-1-->
- Linux Linux_kernel:2.6.31:Rc5<!--2000-1-1-->
- Linux Linux_kernel:2.6.20.12<!--2000-1-1-->
- Linux Linux_kernel:2.6.20.14<!--2000-1-1-->
补丁
暂无
还没有评论,来说两句吧...