CVE-2008-2729

arch/x86_64/lib/copy_user.S in the Linux kernel before 2.6.19 on some AMD64 systems does not erase destination memory locations after an exception during kernel memory copy, which allows local users to obtain sensitive information.
References
Link Resource
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commitdiff%3Bh=3022d734a54cbd2b65eea9a024564821101b4a9a%3Bhp=f0f4c3432e5e1087b3a8c0e6bd4113d3c37497ff
http://rhn.redhat.com/errata/RHSA-2008-0508.html Third Party Advisory
http://secunia.com/advisories/30849 Broken Link
http://secunia.com/advisories/30850 Broken Link
http://secunia.com/advisories/31107 Broken Link
http://secunia.com/advisories/31551 Broken Link
http://secunia.com/advisories/31628 Broken Link
http://www.debian.org/security/2008/dsa-1630 Third Party Advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2008:174 Broken Link
http://www.redhat.com/support/errata/RHSA-2008-0519.html Broken Link
http://www.redhat.com/support/errata/RHSA-2008-0585.html Broken Link
http://www.securityfocus.com/bid/29943 Third Party Advisory VDB Entry
http://www.securitytracker.com/id?1020364 Third Party Advisory VDB Entry
http://www.ubuntu.com/usn/usn-625-1 Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=451271 Issue Tracking Third Party Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/43558 Third Party Advisory VDB Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11571 Tool Signature
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commitdiff%3Bh=3022d734a54cbd2b65eea9a024564821101b4a9a%3Bhp=f0f4c3432e5e1087b3a8c0e6bd4113d3c37497ff
http://rhn.redhat.com/errata/RHSA-2008-0508.html Third Party Advisory
http://secunia.com/advisories/30849 Broken Link
http://secunia.com/advisories/30850 Broken Link
http://secunia.com/advisories/31107 Broken Link
http://secunia.com/advisories/31551 Broken Link
http://secunia.com/advisories/31628 Broken Link
http://www.debian.org/security/2008/dsa-1630 Third Party Advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2008:174 Broken Link
http://www.redhat.com/support/errata/RHSA-2008-0519.html Broken Link
http://www.redhat.com/support/errata/RHSA-2008-0585.html Broken Link
http://www.securityfocus.com/bid/29943 Third Party Advisory VDB Entry
http://www.securitytracker.com/id?1020364 Third Party Advisory VDB Entry
http://www.ubuntu.com/usn/usn-625-1 Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=451271 Issue Tracking Third Party Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/43558 Third Party Advisory VDB Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11571 Tool Signature
Configurations

Configuration 1 (hide)

cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

21 Nov 2024, 00:47

Type Values Removed Values Added
References () http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commitdiff%3Bh=3022d734a54cbd2b65eea9a024564821101b4a9a%3Bhp=f0f4c3432e5e1087b3a8c0e6bd4113d3c37497ff - () http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commitdiff%3Bh=3022d734a54cbd2b65eea9a024564821101b4a9a%3Bhp=f0f4c3432e5e1087b3a8c0e6bd4113d3c37497ff -
References () http://rhn.redhat.com/errata/RHSA-2008-0508.html - Third Party Advisory () http://rhn.redhat.com/errata/RHSA-2008-0508.html - Third Party Advisory
References () http://secunia.com/advisories/30849 - Broken Link () http://secunia.com/advisories/30849 - Broken Link
References () http://secunia.com/advisories/30850 - Broken Link () http://secunia.com/advisories/30850 - Broken Link
References () http://secunia.com/advisories/31107 - Broken Link () http://secunia.com/advisories/31107 - Broken Link
References () http://secunia.com/advisories/31551 - Broken Link () http://secunia.com/advisories/31551 - Broken Link
References () http://secunia.com/advisories/31628 - Broken Link () http://secunia.com/advisories/31628 - Broken Link
References () http://www.debian.org/security/2008/dsa-1630 - Third Party Advisory () http://www.debian.org/security/2008/dsa-1630 - Third Party Advisory
References () http://www.mandriva.com/security/advisories?name=MDVSA-2008:174 - Broken Link () http://www.mandriva.com/security/advisories?name=MDVSA-2008:174 - Broken Link
References () http://www.redhat.com/support/errata/RHSA-2008-0519.html - Broken Link () http://www.redhat.com/support/errata/RHSA-2008-0519.html - Broken Link
References () http://www.redhat.com/support/errata/RHSA-2008-0585.html - Broken Link () http://www.redhat.com/support/errata/RHSA-2008-0585.html - Broken Link
References () http://www.securityfocus.com/bid/29943 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/29943 - Third Party Advisory, VDB Entry
References () http://www.securitytracker.com/id?1020364 - Third Party Advisory, VDB Entry () http://www.securitytracker.com/id?1020364 - Third Party Advisory, VDB Entry
References () http://www.ubuntu.com/usn/usn-625-1 - Third Party Advisory () http://www.ubuntu.com/usn/usn-625-1 - Third Party Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=451271 - Issue Tracking, Third Party Advisory () https://bugzilla.redhat.com/show_bug.cgi?id=451271 - Issue Tracking, Third Party Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/43558 - Third Party Advisory, VDB Entry () https://exchange.xforce.ibmcloud.com/vulnerabilities/43558 - Third Party Advisory, VDB Entry
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11571 - Tool Signature () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11571 - Tool Signature

07 Nov 2023, 02:02

Type Values Removed Values Added
References
  • {'url': 'http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=3022d734a54cbd2b65eea9a024564821101b4a9a;hp=f0f4c3432e5e1087b3a8c0e6bd4113d3c37497ff', 'name': 'http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=3022d734a54cbd2b65eea9a024564821101b4a9a;hp=f0f4c3432e5e1087b3a8c0e6bd4113d3c37497ff', 'tags': ['Exploit', 'Vendor Advisory'], 'refsource': 'CONFIRM'}
  • () http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commitdiff%3Bh=3022d734a54cbd2b65eea9a024564821101b4a9a%3Bhp=f0f4c3432e5e1087b3a8c0e6bd4113d3c37497ff -

Information

Published : 2008-06-30 22:41

Updated : 2024-11-21 00:47


NVD link : CVE-2008-2729

Mitre link : CVE-2008-2729

CVE.ORG link : CVE-2008-2729


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor