Title: Linux Kernel S/390 Copy_From_User Local Information Disclosure Vulnerability
Severity: MODERATE
Description:
The Linux kernel is prone to a local information-disclosure vulnerability on the S/390 architecture because the kernel fails to properly initialize kernel memory prior to returning it to user-space programs.
Specifically, if an attacker appends to a file from an invalid memory address, the 'copy_from_user()' function will receive a fault during a memory read operation. The function then fails to properly clear the remaining memory in the copy operation. Further user-space reads on the file may return potentially sensitive kernel memory.
Successfully exploiting this issue allows local attackers to gain access to potentially sensitive information contained in kernel memory, aiding them in further attacks.
Linux kernel versions prior to 2.6.19-rc1 on the S/390 architecture are vulnerable to this issue.
Affected Products:
- Avaya AES 3.1
- Avaya CCS 2.0
- Avaya CCS 3.0
- Avaya Integrated Management
- Avaya Intuity LX
- Avaya Messaging Storage Server MM3.0
- Avaya S8300
- Avaya S8300 CM 2.0
- Avaya S8300 CM 3.1
- Avaya S8300 R2.0.0
- Avaya S8300 R2.0.1
- Avaya S8500
- Avaya S8500 CM 2.0
- Avaya S8500 CM 3.1
- Avaya S8500 R2.0.0
- Avaya S8500 R2.0.1
- Avaya S8700 CM 2.0
- Avaya S8700 CM 3.1
- Avaya S8700 R2.0.0
- Avaya S8700 R2.0.1
- Avaya S8710 CM 2.0
- Avaya S8710 CM 3.1
- Avaya S8710 R2.0.0
- Avaya S8710 R2.0.1
- Avaya SES 2.0
- Avaya SES 3.0
- Debian Linux 3.1.0
- Debian Linux 3.1.0 alpha
- Debian Linux 3.1.0 amd64
- Debian Linux 3.1.0 arm
- Debian Linux 3.1.0 hppa
- Debian Linux 3.1.0 ia-32
- Debian Linux 3.1.0 ia-64
- Debian Linux 3.1.0 m68k
- Debian Linux 3.1.0 mips
- Debian Linux 3.1.0 mipsel
- Debian Linux 3.1.0 ppc
- Debian Linux 3.1.0 s/390
- Debian Linux 3.1.0 sparc
- Linux kernel 2.6.0
- Linux kernel 2.6.0 -test1
- Linux kernel 2.6.0 -test10
- Linux kernel 2.6.0 -test11
- Linux kernel 2.6.0 -test2
- Linux kernel 2.6.0 -test3
- Linux kernel 2.6.0 -test4
- Linux kernel 2.6.0 -test5
- Linux kernel 2.6.0 -test6
- Linux kernel 2.6.0 -test7
- Linux kernel 2.6.0 -test8
- Linux kernel 2.6.0 -test9
- Linux kernel 2.6.0 -test9-CVS
- Linux kernel 2.6.0 .10
- Linux kernel 2.6.1
- Linux kernel 2.6.1 -rc1
- Linux kernel 2.6.1 -rc2
- Linux kernel 2.6.10
- Linux kernel 2.6.10 rc2
- Linux kernel 2.6.11
- Linux kernel 2.6.11 -rc2
- Linux kernel 2.6.11 -rc3
- Linux kernel 2.6.11 -rc4
- Linux kernel 2.6.11 .11
- Linux kernel 2.6.11 .12
- Linux kernel 2.6.11 .4
- Linux kernel 2.6.11 .5
- Linux kernel 2.6.11 .6
- Linux kernel 2.6.11 .7
- Linux kernel 2.6.11 .8
- Linux kernel 2.6.11.4
- Linux kernel 2.6.12
- Linux kernel 2.6.12 -rc1
- Linux kernel 2.6.12 -rc4
- Linux kernel 2.6.12 -rc5
- Linux kernel 2.6.12 .1
- Linux kernel 2.6.12 .2
- Linux kernel 2.6.12 .3
- Linux kernel 2.6.12 .4
- Linux kernel 2.6.12 .5
- Linux kernel 2.6.12 .6
- Linux kernel 2.6.13
- Linux kernel 2.6.13 -rc1
- Linux kernel 2.6.13 -rc4
- Linux kernel 2.6.13 -rc6
- Linux kernel 2.6.13 -rc7
- Linux kernel 2.6.13 .1
- Linux kernel 2.6.13 .2
- Linux kernel 2.6.13 .3
- Linux kernel 2.6.13 .4
- Linux kernel 2.6.14
- Linux kernel 2.6.14 -rc1
- Linux kernel 2.6.14 -rc2
- Linux kernel 2.6.14 -rc3
- Linux kernel 2.6.14 -rc4
- Linux kernel 2.6.14 .1
- Linux kernel 2.6.14 .2
- Linux kernel 2.6.14 .3
- Linux kernel 2.6.14.4
- Linux kernel 2.6.14.5
- Linux kernel 2.6.15
- Linux kernel 2.6.15 -rc1
- Linux kernel 2.6.15 -rc2
- Linux kernel 2.6.15 -rc3
- Linux kernel 2.6.15 -rc4
- Linux kernel 2.6.15 -rc5
- Linux kernel 2.6.15 -rc6
- Linux kernel 2.6.15 .4
- Linux kernel 2.6.15.1
- Linux kernel 2.6.15.2
- Linux kernel 2.6.15.3
- Linux kernel 2.6.15.5
- Linux kernel 2.6.15.6
- Linux kernel 2.6.16
- Linux kernel 2.6.16 -rc1
- Linux kernel 2.6.16 .1
- Linux kernel 2.6.16 .11
- Linux kernel 2.6.16 .12
- Linux kernel 2.6.16 .19
- Linux kernel 2.6.16 .23
- Linux kernel 2.6.16 .7
- Linux kernel 2.6.16 .9
- Linux kernel 2.6.16 13
- Linux kernel 2.6.16 27
- Linux kernel 2.6.16.16
- Linux kernel 2.6.16.17
- Linux kernel 2.6.16.18
- Linux kernel 2.6.16.2
- Linux kernel 2.6.16.21
- Linux kernel 2.6.16.3
- Linux kernel 2.6.16.4
- Linux kernel 2.6.16.5
- Linux kernel 2.6.16.8
- Linux kernel 2.6.17
- Linux kernel 2.6.17
- Linux kernel 2.6.17
- Linux kernel 2.6.17 -rc5
- Linux kernel 2.6.17 .8
- Linux kernel 2.6.17.1
- Linux kernel 2.6.17.10
- Linux kernel 2.6.17.11
- Linux kernel 2.6.17.3
- Linux kernel 2.6.17.4
- Linux kernel 2.6.17.5
- Linux kernel 2.6.17.6
- Linux kernel 2.6.17.7
- Linux kernel 2.6.17.9
- Linux kernel 2.6.18
- Linux kernel 2.6.2
- Linux kernel 2.6.3
- Linux kernel 2.6.4
- Linux kernel 2.6.5
- Linux kernel 2.6.6
- Linux kernel 2.6.6 rc1
- Linux kernel 2.6.7
- Linux kernel 2.6.7 rc1
- Linux kernel 2.6.8
- Linux kernel 2.6.8 rc1
- Linux kernel 2.6.8 rc2
- Linux kernel 2.6.8 rc3
- Linux kernel 2.6.9
- RedHat Desktop 3.0.0
- RedHat Desktop 4.0.0
- RedHat Enterprise Linux AS 3
- RedHat Enterprise Linux AS 4
- RedHat Enterprise Linux ES 3
- RedHat Enterprise Linux ES 4
- RedHat Enterprise Linux WS 3
- RedHat Enterprise Linux WS 4
- RedHat Fedora Core2
- RedHat Fedora Core3
- RedHat Fedora Core4
- S.u.S.E. Linux Enterprise Server 9
- S.u.S.E. Linux Personal 10.0.0 OSS
- S.u.S.E. Linux Personal 10.1
- S.u.S.E. Linux Personal 9.1.0
- S.u.S.E. Linux Personal 9.1.0 x86_64
- S.u.S.E. Linux Personal 9.2.0
- S.u.S.E. Linux Personal 9.2.0 x86_64
- S.u.S.E. Linux Personal 9.3.0
- S.u.S.E. Linux Personal 9.3.0 x86_64
- S.u.S.E. Linux Professional 10.0.0 OSS
- S.u.S.E. Linux Professional 10.1
- S.u.S.E. Linux Professional 9.3.0
- S.u.S.E. Linux Professional 9.3.0 x86_64
- S.u.S.E. Novell Linux Desktop 9.0.0
- S.u.S.E. Novell Linux POS 9
- S.u.S.E. Open-Enterprise-Server
- S.u.S.E. SUSE Linux Enterprise Desktop 10
- S.u.S.E. SUSE Linux Enterprise Server 10
- Trustix Secure Enterprise Linux 2.0.0
- Trustix Secure Linux 2.0.0
- Trustix Secure Linux 2.1.0
- Trustix Secure Linux 2.2.0
- Trustix Secure Linux 3.0.0
- Ubuntu Ubuntu Linux 4.1.0 ia32
- Ubuntu Ubuntu Linux 4.1.0 ia64
- Ubuntu Ubuntu Linux 4.1.0 ppc
- Ubuntu Ubuntu Linux 5.0.0 4 amd64
- Ubuntu Ubuntu Linux 5.0.0 4 i386
- Ubuntu Ubuntu Linux 5.0.0 4 powerpc
References:
- Avaya: ASA-2007-063 - kernel security update (RHSA-2007-0014)
- Linux Kernel: Linux 2.6.18.1 ChangeLog
- Linux Kernel: [S390] user readable uninitialised kernel memory.
- Redhat: RHSA-2007:0014-6
Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.