VulnerabilityModified
CVE-2008-2729
arch/x86_64/lib/copy_user.S in the Linux kernel before 2.6.19 on some AMD64 systems does not erase destination memory locations after an exception during kernel memory copy, which allows local users to obtain sensitive information.
MEDIUM 4.9EPSS 0.57%
Does this matter?
Lower severity and a low EPSS score (0.57%). Track it; it rarely justifies an emergency change on its own.
Description
arch/x86_64/lib/copy_user.S in the Linux kernel before 2.6.19 on some AMD64 systems does not erase destination memory locations after an exception during kernel memory copy, which allows local users to obtain sensitive information.
- CVSS 2.0
- 4.9 MEDIUMAV:L/AC:L/Au:N/C:C/I:N/A:N
- EPSS
- 0.57% probability · 45th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- linux/linux kernel
- Source
- cve@mitre.org
References
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commitdiff%3Bh=3022d734a54cbd2b65eea9a024564821101b4a9a%3Bhp=f0f4c3432e5e1087b3a8c0e6bd4113d3c37497ff
- http://rhn.redhat.com/errata/RHSA-2008-0508.htmlThird Party Advisory
- http://secunia.com/advisories/30849Broken Link
- http://secunia.com/advisories/30850Broken Link
- http://secunia.com/advisories/31107Broken Link
- http://secunia.com/advisories/31551Broken Link
- http://secunia.com/advisories/31628Broken Link
- http://www.debian.org/security/2008/dsa-1630Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:174Broken Link
- http://www.redhat.com/support/errata/RHSA-2008-0519.htmlBroken Link
- http://www.redhat.com/support/errata/RHSA-2008-0585.htmlBroken Link
- http://www.securityfocus.com/bid/29943Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1020364Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/usn-625-1Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=451271Issue Tracking, Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43558Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11571Tool Signature
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commitdiff%3Bh=3022d734a54cbd2b65eea9a024564821101b4a9a%3Bhp=f0f4c3432e5e1087b3a8c0e6bd4113d3c37497ff
- http://rhn.redhat.com/errata/RHSA-2008-0508.htmlThird Party Advisory
- http://secunia.com/advisories/30849Broken Link
- http://secunia.com/advisories/30850Broken Link
- http://secunia.com/advisories/31107Broken Link
- http://secunia.com/advisories/31551Broken Link
- http://secunia.com/advisories/31628Broken Link
- http://www.debian.org/security/2008/dsa-1630Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:174Broken Link
- http://www.redhat.com/support/errata/RHSA-2008-0519.htmlBroken Link
- http://www.redhat.com/support/errata/RHSA-2008-0585.htmlBroken Link
- http://www.securityfocus.com/bid/29943Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1020364Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.