Back

LOW

kernel: crypto: info leaks in report API

Published Mar 14, 2013

Description

The crypto_report_one function in crypto/crypto_user.c in the report API in the crypto user configuration API in the Linux kernel through 3.8.2 does not initialize certain structure members, which allows local users to obtain sensitive information from kernel heap memory by leveraging the CAP_NET_ADMIN capability.

Affected products

Remediation

Red Hat statement

These issues do not affect the versions of the kernel package as shipped with Red Hat Enterprise Linux 5 and Red Hat Enterprise Linux 6. These issues do affect the version of Linux kernel as shipped with Red Hat Enterprise MRG 2. Future kernel updates for Red Hat Enterprise MRG 2 may address this issue.

Metrics

Weaknesses (1)

References (14)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 14, 2013
Updated Aug 6, 2024
Reserved Mar 8, 2013
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Feb 5, 2013