Array index error in the aio_read_events_ring function in fs/aio.c in the Linux kernel through 3.15.1 allows local users to obtain sensitive information from kernel memory via a large head value.
CVSS Details
- CVSS 3.1 Base Score: 3.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jul 30, 2024 | Jun 25, 2014 |
| Oracle_linux | — | Upgrade kernel | Oct 16, 2024 | Jun 25, 2014 |
| Suse | — | Upgrade kernel-default | Dec 18, 2015 | Jun 25, 2014 |
| Ubuntu | — | Upgrade linux-image-3.13.0-35-powerpc-e500mcUpgrade linux-image-3.13.0-35-powerpc-e500Upgrade linux-image-3.13.0-35-genericUpgrade linux-image-3.13.0-35-powerpc64-embUpgrade linux-image-3.13.0-35-generic-lpaeUpgrade linux-image-3.13.0-35-lowlatencyUpgrade linux-image-3.13.0-35-powerpc64-smpUpgrade linux-image-3.13.0-35-powerpc-smp | Nov 8, 2024 | Jun 25, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub