Upstream information

CVE-2010-4525 at MITRE

Description

Linux kernel 2.6.33 and 2.6.34.y does not initialize the kvm_vcpu_events->interrupt.pad structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via unspecified vectors.

SUSE information

Overall state of this security issue: Resolved

This issue is currently rated as having moderate severity.

CVSS v2 Scores
  National Vulnerability Database
Base Score 1.9
Vector AV:L/AC:M/Au:N/C:P/I:N/A:N
Access Vector Local
Access Complexity Medium
Authentication None
Confidentiality Impact Partial
Integrity Impact None
Availability Impact None
SUSE Bugzilla entry: 662663 [RESOLVED / FIXED]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SUSE Linux Enterprise Real Time Extension 11 SP1
  • brocade-bna-kmp-rt >= 2.1.0.0_2.6.33.18_rt31_0.3-0.2.24
  • cluster-network-kmp-rt >= 1.4_2.6.33.18_rt31_0.3-2.5.6
  • cluster-network-kmp-rt_trace >= 1.4_2.6.33.18_rt31_0.3-2.5.6
  • drbd-kmp-rt >= 8.3.11_2.6.33.18_rt31_0.3-0.3.6
  • drbd-kmp-rt_trace >= 8.3.11_2.6.33.18_rt31_0.3-0.3.6
  • iscsitarget-kmp-rt >= 1.4.19_2.6.33.18_rt31_0.3-0.7.48
  • kernel-rt >= 2.6.33.18-0.3.1
  • kernel-rt-base >= 2.6.33.18-0.3.1
  • kernel-rt-devel >= 2.6.33.18-0.3.1
  • kernel-rt_trace >= 2.6.33.18-0.3.1
  • kernel-rt_trace-base >= 2.6.33.18-0.3.1
  • kernel-rt_trace-devel >= 2.6.33.18-0.3.1
  • kernel-source-rt >= 2.6.33.18-0.3.1
  • kernel-syms-rt >= 2.6.33.18-0.3.1
  • ocfs2-kmp-rt >= 1.6_2.6.33.18_rt31_0.3-0.4.2.6
  • ocfs2-kmp-rt_trace >= 1.6_2.6.33.18_rt31_0.3-0.4.2.6
  • ofed-kmp-rt >= 1.4.2_2.6.33.7.2_rt30_0.3-0.14.1
Patchnames:
slertesp1-kernel