The ocfs2_prepare_page_for_write function in fs/ocfs2/aops.c in the Oracle Cluster File System 2 (OCFS2) subsystem in the Linux kernel before 2.6.39-rc1 does not properly handle holes that cross page boundaries, which allows local users to obtain potentially sensitive information from uninitialized disk locations by reading a file.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://www.ubuntu.com/usn/USN-1146-1 | third party advisory vendor advisory |
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=272b62c1f0f6f742046e45b50b6fec98860208a0 | |
http://secunia.com/advisories/43966 | third party advisory |
https://bugzilla.novell.com/show_bug.cgi?id=673037 | issue tracking exploit third party advisory |
http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.39-rc1 | release notes vendor advisory |
http://oss.oracle.com/pipermail/ocfs2-devel/2011-February/007846.html | mailing list exploit third party advisory patch |