Bug 142251

Summary: VUL-0: kernel: dm-crypt information leak
Product: [openSUSE] SUSE LINUX 10.0 Reporter: Marcus Meissner <meissner>
Component: KernelAssignee: Security Team bot <security-team>
Status: RESOLVED FIXED QA Contact: E-mail List <qa-bugs>
Severity: Minor    
Priority: P5 - None CC: nfbrown, security-team
Version: Final   
Target Milestone: ---   
Hardware: Other   
OS: Other   
Whiteboard: affected:sles9sp4,sles9sp3, 9.2,9.3,10.0 applied:sles9sp4,sles9sp3,9 .2,9.3.10.0 released: - CVE-2006-0095: CVSS v2 Base Score: 2.1 (AV:L/AC:L/Au:N/C:P/I:N/A:N )
Found By: Other Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---
Attachments: The patch from 9.3

Description Marcus Meissner 2006-01-10 09:44:18 UTC
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0095

only a minor problem in my eyes.

dm-crypt in Linux kernel 2.6.15 and earlier does not clear a structure before it is freed, which leads to a memory disclosure that could allow local users to obtain sensitive information about a cryptographic key.
Comment 2 Neil Brown 2006-01-24 04:56:50 UTC
The current sles10 CVS has this fixed as it based on -git9.
I have backported into sles9-sp4, fixing it on the way.

I've reported the problem with the patch to Authors and linux-kernel.

Maybe I'll add the fix to HEAD once it gets to mainline....

Comment 3 Marcus Meissner 2006-01-26 17:31:01 UTC
this likely applies to the other kernel branches too, right?
Comment 4 Neil Brown 2006-02-24 00:09:56 UTC
Created attachment 70077 [details]
The patch from 9.3

Here is the patch from 9.3 which should replace the one in SLES9-SP3
Comment 5 Neil Brown 2006-02-24 00:11:12 UTC
Oops.... wrong bug... now how did I do that....

Sorry, forget comment #4 and comment #5.
Comment 6 Marcus Meissner 2006-04-25 11:15:17 UTC
can you/someone else apply the patch to the other active branches?

cvs tags are listed in:
http://w3d.suse.de/Dev/Labs/Pubs/Kernel_Building.html
Comment 7 Neil Brown 2006-04-27 03:03:46 UTC
Ok, I've applied it and updated the status whiteboard.

NeilBrown
Comment 8 Marcus Meissner 2006-04-27 08:49:44 UTC
thanks neil!
Comment 9 Marcus Meissner 2006-05-03 06:43:30 UTC
marking fixed, since all done exccept pushing out via update.
Comment 10 Thomas Biege 2009-10-13 23:07:31 UTC
CVE-2006-0095: CVSS v2 Base Score: 2.1 (AV:L/AC:L/Au:N/C:P/I:N/A:N)