The Linux kernel before 3.12.4 updates certain length values before ensuring that associated data structures have been initialized, which allows local users to obtain sensitive information from kernel stack memory via a (1) recvfrom, (2) recvmmsg, or (3) recvmsg system call, related to net/ipv4/ping.c, net/ipv4/raw.c, net/ipv4/udp.c, net/ipv6/raw.c, and net/ipv6/udp.c.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2014-01-06 16:55
Updated : 2024-02-04 18:16
NVD link : CVE-2013-7263
Mitre link : CVE-2013-7263
CVE.ORG link : CVE-2013-7263
JSON object : View
Products Affected
linux
- linux_kernel
CWE
CWE-20
Improper Input Validation