CVE-2014-4027
LOW severity · CVSS 2.3 · Information disclosure
2.3CVSS LOW
Summary
The rd_build_device_space function in drivers/target/target_core_rd.c in the Linux kernel before 3.14 does not properly initialize a certain data structure, which allows local users to obtain sensitive information from ramdisk_mcp memory by leveraging access to a SCSI initiator.
Impact & exploitability
Attack vectorAdjacent
Attack complexity—
Privileges required—
User interaction—
Confidentiality impact—
Integrity impactNone
Availability impactNone
Exploit probability (EPSS)1%
AV:A/AC:M/Au:S/C:P/I:N/A:N
Affected products we track (2)
Recommendation
Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.
Additional information
- NVD record
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=4442dc8a92b8f9ad8ee9e7f8438f4c04c03a22dc
- http://lists.opensuse.org/opensuse-security-announce/2014-10/msg00006.htmlAdvisory
- http://lists.opensuse.org/opensuse-security-announce/2014-10/msg00007.htmlAdvisory
- http://permalink.gmane.org/gmane.linux.scsi.target.devel/6618
- http://secunia.com/advisories/59134
- http://secunia.com/advisories/59777
- http://secunia.com/advisories/60564
- http://secunia.com/advisories/61310