Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.
For bugs related to Red Hat Enterprise Linux 4 product line. The current stable release is 4.9. For Red Hat Enterprise Linux 6 and above, please visit Red Hat JIRA https://issues.redhat.com/secure/CreateIssue!default.jspa?pid=12332745 to report new issues.

Bug 176812

Summary: CVE-2005-4605 Kernel memory disclosure
Product: Red Hat Enterprise Linux 4 Reporter: Mark J. Cox <mjc>
Component: kernelAssignee: Jason Baron <jbaron>
Status: CLOSED ERRATA QA Contact: Brian Brock <bbrock>
Severity: high Docs Contact:
Priority: medium    
Version: 4.0CC: andriusb, jbaron, knoel
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard: reported=20051230,source=fulldisclosure,public=20051223,impact=important
Fixed In Version: RHSA-2006-0101 Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2006-01-17 08:37:09 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 168430    

Description Mark J. Cox 2006-01-03 09:08:57 UTC
Reported to full-disclosure was a flaw said to allow kernel memory to be
disclosed to untrusted local users.  This was verified by Solar Designer and a
patch for the issue committed by Linus.

Original report:
http://marc.theaimsgroup.com/?l=full-disclosure&m=113535380422339

Fix:
http://linux.bkbits.net:8080/linux-2.6/cset@43b562ae6hJGLWZA4TNf2k-RzXnVlQ

Comment 2 David Woodhouse 2006-01-04 18:37:25 UTC
Is BK still going? 

The canonical location would now be in git:
http://git.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=8b90db0df7187a01fb7177f1f812123138f562cf

Comment 3 Mark J. Cox 2006-01-04 18:54:18 UTC
yeah, we track all the outstanding issues by bk id at the moment (one form so
that we can easily spot dupes).  We need to go through and convert them all to
git ids at some point.

Comment 11 Red Hat Bugzilla 2006-01-17 08:37:11 UTC
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.

http://rhn.redhat.com/errata/RHSA-2006-0101.html