Linux kernel built with Asynchronous Transfer Mode(ATM) support is vulnerable to an information leakage flaw. It occurs when doing getsockopt(SO_AMTPVC) and getsockname() calls. A user/program could use this flaw to leak kernel memory bytes. Upstream fix: ------------- -> https://git.kernel.org/linus/3c0c5cfdcd4d69ffc4b9c0907cec99039f30a50a -> https://git.kernel.org/linus/e862f1a9b7df4e8196ebec45ac62295138aa3fc2 Reference: ---------- -> http://www.openwall.com/lists/oss-security/2013/03/14/21
Statement: This issue does not affect the versions of the kernel package as shipped with Red Hat Enterprise MRG 2. This issue did affect the version of the Linux kernel as shipped with Red Hat Enterprise Linux 5 and Red Hat Enterprise Linux 6.
This issue has been addressed in following products: Red Hat Enterprise Linux 5 Via RHSA-2013:0747 https://rhn.redhat.com/errata/RHSA-2013-0747.html
This issue has been addressed in following products: Red Hat Enterprise Linux 6 Via RHSA-2013:0744 https://rhn.redhat.com/errata/RHSA-2013-0744.html