Bug 176813

Summary: CVE-2005-4605 Kernel memory disclosure
Product: [Fedora] Fedora Reporter: Mark J. Cox <mjc>
Component: kernelAssignee: Dave Jones <davej>
Status: CLOSED CURRENTRELEASE QA Contact: Brian Brock <bbrock>
Severity: high Docs Contact:
Priority: medium    
Version: 4CC: pfrields, wtogami
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard: reported=20051230,source=fulldisclosure,public=20051223,impact=important
Fixed In Version: FEDORA-2006-013 Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2006-02-03 08:43:32 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Mark J. Cox 2006-01-03 09:13:27 UTC
+++ This bug was initially created as a clone of Bug #176812 +++

Reported to full-disclosure was a flaw said to allow kernel memory to be
disclosed to untrusted local users.  This was verified by Solar Designer and a
patch for the issue committed by Linus.

Original report:
http://marc.theaimsgroup.com/?l=full-disclosure&m=113535380422339

Fix:
http://linux.bkbits.net:8080/linux-2.6/cset@43b562ae6hJGLWZA4TNf2k-RzXnVlQ

(See cloned bug for non-public reproducer)

Comment 1 Dave Jones 2006-01-04 05:29:10 UTC
fixed in cvs, will go out in the next fc4 update.


Comment 2 Dave Jones 2006-02-03 05:36:42 UTC
This is a mass-update to all currently open kernel bugs.

A new kernel update has been released (Version: 2.6.15-1.1830_FC4)
based upon a new upstream kernel release.

Please retest against this new kernel, as a large number of patches
go into each upstream release, possibly including changes that
may address this problem.

This bug has been placed in NEEDINFO_REPORTER state.
Due to the large volume of inactive bugs in bugzilla, if this bug is
still in this state in two weeks time, it will be closed.

Should this bug still be relevant after this period, the reporter
can reopen the bug at any time. Any other users on the Cc: list
of this bug can request that the bug be reopened by adding a
comment to the bug.

If this bug is a problem preventing you from installing the
release this version is filed against, please see bug 169613.

Thank you.