CVE Database
/

CVE-2013-2147

Back to search

CVE-2013-2147

Published: Jun 7, 2013

Modified: Aug 6, 2024

PUBLISHED

Description

The HP Smart Array controller disk-array driver and Compaq SMART2 controller disk-array driver in the Linux kernel through 3.9.4 do not initialize certain data structures, which allows local users to obtain sensitive information from kernel memory via (1) a crafted IDAGETPCIINFO command for a /dev/ida device, related to the ida_locked_ioctl function in drivers/block/cpqarray.c or (2) a crafted CCISS_PASSTHRU32 command for a /dev/cciss device, related to the cciss_ioctl32_passthru function in drivers/block/cciss.c.

VendorProductVersions

n/a

n/a

affected
n/a

References

USN-2015-1
vendor-advisory
x_refsource_UBUNTU
RHSA-2013:1166
vendor-advisory
x_refsource_REDHAT
USN-1996-1
vendor-advisory
x_refsource_UBUNTU
USN-1994-1
vendor-advisory
x_refsource_UBUNTU
USN-1997-1
vendor-advisory
x_refsource_UBUNTU
USN-2016-1
vendor-advisory
x_refsource_UBUNTU
USN-2020-1
vendor-advisory
x_refsource_UBUNTU
USN-2017-1
vendor-advisory
x_refsource_UBUNTU
USN-2023-1
vendor-advisory
x_refsource_UBUNTU
USN-2050-1
vendor-advisory
x_refsource_UBUNTU
USN-1999-1
vendor-advisory
x_refsource_UBUNTU
SUSE-SU-2015:0812
vendor-advisory
x_refsource_SUSE

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now