SB2002123106 - Missing release of memory after effective lifetime in Linux kernel



SB2002123106 - Missing release of memory after effective lifetime in Linux kernel

Published: December 31, 2002

Security Bulletin ID SB2002123106
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Missing release of memory after effective lifetime (CVE-ID: CVE-2002-1571)

The vulnerability allows a local user to gain access to sensitive information.

The linux 2.4 kernel before 2.4.19 assumes that the fninit instruction clears all registers, which could lead to an information leak on processors that do not clear all relevant SSE registers.


Remediation

Install update from vendor's website.