CVE-2013-3237
22.04.2013, 11:41
The vsock_stream_sendmsg function in net/vmw_vsock/af_vsock.c in the Linux kernel before 3.9-rc7 does not initialize a certain length variable, which allows local users to obtain sensitive information from kernel stack memory via a crafted recvmsg or recvfrom system call.Enginsight
Vendor | Product | Version |
---|---|---|
linux | linux_kernel | 𝑥 ≤ 3.9 |
linux | linux_kernel | 3.9:rc1 |
linux | linux_kernel | 3.9:rc2 |
linux | linux_kernel | 3.9:rc3 |
linux | linux_kernel | 3.9:rc4 |
linux | linux_kernel | 3.9:rc5 |
𝑥
= Vulnerable software versions

Debian Releases
Debian Product | |||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
linux |
| ||||||||||||||||
open-vm-tools |
|

Ubuntu Releases
Ubuntu Product | |||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
linux |
| ||||||||||||
linux-armadaxp |
| ||||||||||||
linux-ec2 |
| ||||||||||||
linux-fsl-imx51 |
| ||||||||||||
linux-linaro-omap |
| ||||||||||||
linux-linaro-shared |
| ||||||||||||
linux-linaro-vexpress |
| ||||||||||||
linux-lts-backport-maverick |
| ||||||||||||
linux-lts-backport-oneiric |
| ||||||||||||
linux-lts-quantal |
| ||||||||||||
linux-lts-raring |
| ||||||||||||
linux-mvl-dove |
| ||||||||||||
linux-qcm-msm |
| ||||||||||||
linux-ti-omap4 |
|
Common Weakness Enumeration
References