The ib_uverbs_poll_cq function in drivers/infiniband/core/uverbs_cmd.c in the Linux kernel before 2.6.37 does not initialize a certain response buffer, which allows local users to obtain potentially sensitive information from kernel memory via vectors that cause this buffer to be only partially filled, a different vulnerability than CVE-2010-4649.
The product does not initialize a critical resource.
Link | Tags |
---|---|
http://rhn.redhat.com/errata/RHSA-2011-0927.html | third party advisory vendor advisory |
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=7182afea8d1afd432a17c18162cc3fd441d0da93 | |
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.37 | broken link |
https://bugzilla.redhat.com/show_bug.cgi?id=667916 | issue tracking third party advisory patch |
https://exchange.xforce.ibmcloud.com/vulnerabilities/65563 | vdb entry third party advisory |
http://www.securityfocus.com/bid/46488 | vdb entry third party advisory |