Linux kernel built with XFRM framework support is vulnerable to a memory leakage flaw. It occurs in routine - copy_to_user_auth - when it fails to correctly initialise the variable: alg_name. An user/program could use this flaw to leak kernel memory bytes. Upstream fix: ------------- -> https://git.kernel.org/linus/4c87308bdea31a7b4828a51f6156e6f721a1fcc9 Reference: ---------- -> http://www.openwall.com/lists/oss-security/2013/03/14/21
Statement: This issue does not affect the versions of the kernel package as shipped with Red Hat Enterprise Linux 5 and Red Hat Enterprise MRG 2. This issue affects the versions of Linux kernel as shipped with Red Hat Enterprise Linux 6 . This issue has been addressed in Red Hat Enterprise Linux 6 via https://rhn.redhat.com/errata/RHSA-2013-0744.html.
This issue has been addressed in following products: Red Hat Enterprise Linux 6 Via RHSA-2013:0744 https://rhn.redhat.com/errata/RHSA-2013-0744.html