Linux kernel built with IOS FS (CONFIG_ISO9660_FS) support is vulnerable to an information leakage flaw. It occurs when doing an export operation via routine - isofs_export_encode_fh - reachable from - name_to_handle_at - syscall. A user/program could use this flaw to leak kernel memory bytes. Upstream fix: ------------- -> https://git.kernel.org/linus/fe685aabf7c8c9f138e5ea900954d295bf229175 Reference: ---------- -> http://www.openwall.com/lists/oss-security/2013/03/14/21
Statement: This issue does not affect the versions of the kernel package as shipped with Red Hat Enterprise Linux 5, 6 and Red Hat Enterprise MRG 2.