Bug 177137 - CVE-2006-0095 dm-crypt key leak
Summary: CVE-2006-0095 dm-crypt key leak
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: kernel   
(Show other bugs)
Version: 4
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Dave Jones
QA Contact: Brian Brock
URL:
Whiteboard: reported=20060106,source=lkml,public=...
Keywords: Security
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2006-01-06 16:48 UTC by Mark J. Cox
Modified: 2015-01-04 22:24 UTC (History)
2 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2006-02-10 21:15:58 UTC
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

Description Mark J. Cox 2006-01-06 16:48:44 UTC
+++ This bug was initially created as a clone of Bug #177136 +++

CVE-2006-0095 says:
        dm-crypt in Linux kernel 2.6.15 and earlier does not clear a
        structure before it is freed, which leads to a memory
        disclosure that could allow local users to obtain sensitive
        information about a cryptographic key.

More details and the straightforward patch are here:

        http://marc.theaimsgroup.com/?l=linux-kernel&m=113640535312572
        http://marc.theaimsgroup.com/?l=linux-kernel&m=113641114812886

Comment 1 Dave Jones 2006-02-03 05:47:04 UTC
This is a mass-update to all currently open kernel bugs.

A new kernel update has been released (Version: 2.6.15-1.1830_FC4)
based upon a new upstream kernel release.

Please retest against this new kernel, as a large number of patches
go into each upstream release, possibly including changes that
may address this problem.

This bug has been placed in NEEDINFO_REPORTER state.
Due to the large volume of inactive bugs in bugzilla, if this bug is
still in this state in two weeks time, it will be closed.

Should this bug still be relevant after this period, the reporter
can reopen the bug at any time. Any other users on the Cc: list
of this bug can request that the bug be reopened by adding a
comment to the bug.

If this bug is a problem preventing you from installing the
release this version is filed against, please see bug 169613.

Thank you.


Comment 2 Mark J. Cox 2006-02-03 08:22:03 UTC
not fixed in 2.6.15 or by backported patch

Comment 3 Dave Jones 2006-02-03 19:10:00 UTC
ok, fixed in cvs, and pushed to upstream -stable maintainers.
I erroneously thought that this was covered in 2.6.15.2



Note You need to log in before you can comment on or make changes to this bug.