Linux kernel built with the Layer Two Tunneling Protocol (CONFIG_L2TP) support is vulnerable to an information leakage flaw. It occurs while receiving messages via recvmsg(2) call. A user/program could use this flaw to leak kernel memory bytes. Upstream fix: ------------- -> http://git.kernel.org/linus/b860d3cc62877fad02863e2a08efff69a19382d2 Reference: ---------- -> http://www.openwall.com/lists/oss-security/2013/04/14/3
Statement: This issue does not affect the versions of the kernel package as shipped with Red Hat Enterprise Linux 5, 6 and Red Hat Enterprise MRG 2.
Created kernel tracking bugs for this issue Affects: fedora-all [bug 956089]
kernel-3.8.8-203.fc18 has been pushed to the Fedora 18 stable repository. If problems still persist, please make note of it in this bug report.
kernel-3.8.11-100.fc17 has been pushed to the Fedora 17 stable repository. If problems still persist, please make note of it in this bug report.