CVE-2010-4565
Bug #765007 reported by
Leann Ogasawara
This bug affects 1 person
| Affects | Status | Importance | Assigned to | Milestone | |
|---|---|---|---|---|---|
| linux (Ubuntu) |
Fix Released
|
Undecided
|
Unassigned | ||
| Dapper |
Invalid
|
Undecided
|
Unassigned | ||
| Hardy |
Invalid
|
Undecided
|
Unassigned | ||
| Karmic |
Won't Fix
|
Undecided
|
Unassigned | ||
| Lucid |
Fix Released
|
Undecided
|
Unassigned | ||
| Maverick |
Fix Released
|
Low
|
Leann Ogasawara | ||
| Natty |
Fix Released
|
Undecided
|
Unassigned | ||
| Oneiric |
Fix Released
|
Undecided
|
Unassigned | ||
| linux-fsl-imx51 (Ubuntu) |
Invalid
|
Undecided
|
Unassigned | ||
| Dapper |
Invalid
|
Undecided
|
Unassigned | ||
| Hardy |
Invalid
|
Undecided
|
Unassigned | ||
| Karmic |
Won't Fix
|
Undecided
|
Unassigned | ||
| Lucid |
Fix Released
|
Undecided
|
Paolo Pisati | ||
| Maverick |
Invalid
|
Undecided
|
Unassigned | ||
| Natty |
Invalid
|
Undecided
|
Unassigned | ||
| Oneiric |
Invalid
|
Undecided
|
Unassigned | ||
| linux-lts-backport-maverick (Ubuntu) |
Invalid
|
Undecided
|
Unassigned | ||
| Dapper |
Invalid
|
Undecided
|
Unassigned | ||
| Hardy |
Invalid
|
Undecided
|
Unassigned | ||
| Karmic |
Invalid
|
Undecided
|
Unassigned | ||
| Lucid |
Fix Released
|
Undecided
|
Unassigned | ||
| Maverick |
Invalid
|
Undecided
|
Unassigned | ||
| Natty |
Invalid
|
Undecided
|
Unassigned | ||
| Oneiric |
Invalid
|
Undecided
|
Unassigned | ||
| linux-mvl-dove (Ubuntu) |
Invalid
|
Undecided
|
Unassigned | ||
| Dapper |
Invalid
|
Undecided
|
Unassigned | ||
| Hardy |
Invalid
|
Undecided
|
Unassigned | ||
| Karmic |
Invalid
|
Undecided
|
Unassigned | ||
| Lucid |
Won't Fix
|
Undecided
|
Unassigned | ||
| Maverick |
Won't Fix
|
Undecided
|
Unassigned | ||
| Natty |
Invalid
|
Undecided
|
Unassigned | ||
| Oneiric |
Invalid
|
Undecided
|
Unassigned | ||
| linux-ti-omap4 (Ubuntu) |
Invalid
|
Undecided
|
Unassigned | ||
| Dapper |
Invalid
|
Undecided
|
Unassigned | ||
| Hardy |
Invalid
|
Undecided
|
Unassigned | ||
| Karmic |
Invalid
|
Undecided
|
Unassigned | ||
| Lucid |
Invalid
|
Undecided
|
Unassigned | ||
| Maverick |
Fix Released
|
Undecided
|
Paolo Pisati | ||
| Natty |
Fix Released
|
Undecided
|
Unassigned | ||
| Oneiric |
Invalid
|
Undecided
|
Unassigned | ||
Bug Description
The bcm_connect function in net/can/bcm.c (aka the Broadcast Manager) in
the Controller Area Network (CAN) implementation in the Linux kernel 2.6.36
and earlier creates a publicly accessible file with a filename containing a
kernel memory address, which allows local users to obtain potentially
sensitive information about kernel memory use by listing this filename.
Related branches
CVE References
- 2010-3296
- 2010-3297
- 2010-3698
- 2010-3858
- 2010-3859
- 2010-3865
- 2010-3875
- 2010-3876
- 2010-3877
- 2010-3880
- 2010-4073
- 2010-4076
- 2010-4077
- 2010-4079
- 2010-4080
- 2010-4081
- 2010-4082
- 2010-4083
- 2010-4157
- 2010-4162
- 2010-4163
- 2010-4164
- 2010-4169
- 2010-4175
- 2010-4242
- 2010-4243
- 2010-4248
- 2010-4256
- 2010-4258
- 2010-4342
- 2010-4346
- 2010-4527
- 2010-4529
- 2010-4565
- 2010-4649
- 2010-4656
- 2011-0463
- 2011-0521
- 2011-0695
- 2011-0711
- 2011-0712
- 2011-0726
- 2011-1010
- 2011-1012
- 2011-1013
- 2011-1016
- 2011-1017
- 2011-1019
- 2011-1020
- 2011-1078
- 2011-1079
- 2011-1080
- 2011-1082
- 2011-1090
- 2011-1093
- 2011-1160
- 2011-1163
- 2011-1169
- 2011-1170
- 2011-1171
- 2011-1172
- 2011-1173
- 2011-1180
- 2011-1478
- 2011-1493
- 2011-1494
- 2011-1577
- 2011-1598
- 2011-1746
- 2011-1748
- 2011-1770
- 2011-1833
- 2011-2484
- 2011-2492
- 2011-2534
- 2011-2699
- 2011-2918
| security vulnerability: | no → yes |
| description: | updated |
| Changed in linux (Ubuntu Maverick): | |
| status: | In Progress → Fix Committed |
| Changed in linux (Ubuntu Lucid): | |
| status: | Fix Committed → Fix Released |
| Changed in linux-mvl-dove (Ubuntu Dapper): | |
| status: | New → Invalid |
| Changed in linux-mvl-dove (Ubuntu Hardy): | |
| status: | New → Invalid |
| Changed in linux-mvl-dove (Ubuntu Karmic): | |
| status: | New → Invalid |
| Changed in linux-mvl-dove (Ubuntu Natty): | |
| status: | New → Invalid |
| Changed in linux-ti-omap4 (Ubuntu Dapper): | |
| status: | New → Invalid |
| Changed in linux-ti-omap4 (Ubuntu Hardy): | |
| status: | New → Invalid |
| Changed in linux-ti-omap4 (Ubuntu Karmic): | |
| status: | New → Invalid |
| Changed in linux-ti-omap4 (Ubuntu Lucid): | |
| status: | New → Invalid |
| Changed in linux-ti-omap4 (Ubuntu Natty): | |
| status: | New → Fix Released |
| Changed in linux-mvl-dove (Ubuntu): | |
| status: | New → Invalid |
| Changed in linux-ti-omap4 (Ubuntu): | |
| status: | New → Invalid |
| Changed in linux-mvl-dove (Ubuntu Lucid): | |
| status: | New → In Progress |
| Changed in linux-ti-omap4 (Ubuntu Maverick): | |
| assignee: | nobody → Paolo Pisati (p-pisati) |
| status: | New → In Progress |
| Changed in linux-fsl-imx51 (Ubuntu Lucid): | |
| assignee: | nobody → Paolo Pisati (p-pisati) |
| status: | New → In Progress |
| tags: | added: kernel-cve-tracking-bug |
| Changed in linux-lts-backport-maverick (Ubuntu Maverick): | |
| status: | New → Invalid |
| Changed in linux-lts-backport-maverick (Ubuntu Natty): | |
| status: | New → Invalid |
| Changed in linux-lts-backport-maverick (Ubuntu Dapper): | |
| status: | New → Invalid |
| Changed in linux-lts-backport-maverick (Ubuntu Hardy): | |
| status: | New → Invalid |
| Changed in linux (Ubuntu Karmic): | |
| status: | New → Won't Fix |
| Changed in linux-lts-backport-maverick (Ubuntu Karmic): | |
| status: | New → Invalid |
| Changed in linux-lts-backport-maverick (Ubuntu Oneiric): | |
| status: | New → Invalid |
| Changed in linux-mvl-dove (Ubuntu Maverick): | |
| status: | New → Won't Fix |
To post a comment you must log in.

Marking Fix Released for Natty:
commit 9f260e0efa4766e 56d0ac14f1aeea6 ee5eb8fe83
Author: Dan Rosenberg <email address hidden>
Date: Sun Dec 26 06:54:53 2010 +0000
CAN: Use inode instead of kernel address for /proc file
~/ubuntu-natty$ git describe --contains 9f260e0efa4766e 56d0ac14f1aeea6 ee5eb8fe83 2.6.37- 12.26~391^ 2~9
Ubuntu-