Back to search
CVE-2009-2910
Published: Oct 20, 2009
Modified: Aug 7, 2024
PUBLISHED
Description
arch/x86/ia32/ia32entry.S in the Linux kernel before 2.6.31.4 on the x86_64 platform does not clear certain kernel registers before a return to user mode, which allows local users to read register values from an earlier process by switching an ia32 process to 64-bit mode.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.31.4
x_refsource_CONFIRM
RHSA-2009:1671
vendor-advisory
x_refsource_REDHAT
RHSA-2009:1540
vendor-advisory
x_refsource_REDHAT
USN-864-1
vendor-advisory
x_refsource_UBUNTU
36927
third-party-advisory
x_refsource_SECUNIA
oval:org.mitre.oval:def:7359
vdb-entry
signature
x_refsource_OVAL
37351
third-party-advisory
x_refsource_SECUNIA
37075
third-party-advisory
x_refsource_SECUNIA
http://support.avaya.com/css/P8/documents/100073666
x_refsource_CONFIRM
SUSE-SA:2009:056
vendor-advisory
x_refsource_SUSE
SUSE-SA:2010:012
vendor-advisory
x_refsource_SUSE
[oss-security] 20091001 Re: CVE Request (kernel)
mailing-list
x_refsource_MLIST
https://bugzilla.redhat.com/show_bug.cgi?id=526788
x_refsource_CONFIRM
oval:org.mitre.oval:def:10823
vdb-entry
signature
x_refsource_OVAL
36576
vdb-entry
x_refsource_BID
[oss-security] 20091002 Re: CVE Request (kernel)
mailing-list
x_refsource_MLIST
[oss-security] 20091009 Re: CVE Request (kernel)
mailing-list
x_refsource_MLIST
[oss-security] 20091001 CVE Request (kernel)
mailing-list
x_refsource_MLIST
FEDORA-2009-10525
vendor-advisory
x_refsource_FEDORA
RHSA-2010:0095
vendor-advisory
x_refsource_REDHAT
RHSA-2010:0046
vendor-advisory
x_refsource_REDHAT
[linux-kernel] 20091001 [tip:x86/urgent] x86: Don't leak 64-bit kernel register values to 32-bit processes
mailing-list
x_refsource_MLIST
SUSE-SA:2009:054
vendor-advisory
x_refsource_SUSE
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now