CVE 2013-6392
The genlock_dev_ioctl function in genlock.c in the Genlock driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not properly initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via a crafted GENLOCK_IOC_EXPORT ioctl call.
Related bugs and status
CVE-2013-6392 (Candidate) is related to these bugs:
Bug #1256095: CVE-2013-6392
Summary | In | Importance | Status | |||
---|---|---|---|---|---|---|
1256095 | CVE-2013-6392 | linux (Ubuntu) | Low | Invalid | ||
1256095 | CVE-2013-6392 | linux-fsl-imx51 (Ubuntu) | Low | Invalid | ||
1256095 | CVE-2013-6392 | linux-mvl-dove (Ubuntu) | Low | Invalid | ||
1256095 | CVE-2013-6392 | linux-lts-backport-maverick (Ubuntu) | Undecided | Won't Fix | ||
1256095 | CVE-2013-6392 | linux-lts-backport-natty (Ubuntu) | Undecided | Won't Fix | ||
1256095 | CVE-2013-6392 | linux-ti-omap4 (Ubuntu) | Low | Invalid | ||
1256095 | CVE-2013-6392 | linux-ec2 (Ubuntu) | Low | Invalid | ||
1256095 | CVE-2013-6392 | linux (Ubuntu Trusty) | Low | Invalid | ||
1256095 | CVE-2013-6392 | linux-ec2 (Ubuntu Trusty) | Low | Invalid | ||
1256095 | CVE-2013-6392 | linux-fsl-imx51 (Ubuntu Trusty) | Low | Invalid | ||
1256095 | CVE-2013-6392 | linux-lts-backport-maverick (Ubuntu Trusty) | Undecided | Won't Fix | ||
1256095 | CVE-2013-6392 | linux-lts-backport-natty (Ubuntu Trusty) | Undecided | Won't Fix | ||
1256095 | CVE-2013-6392 | linux-mvl-dove (Ubuntu Trusty) | Low | Invalid | ||
1256095 | CVE-2013-6392 | linux-ti-omap4 (Ubuntu Trusty) | Low | Invalid | ||
1256095 | CVE-2013-6392 | linux-lts-backport-maverick (Ubuntu Saucy) | Undecided | Won't Fix | ||
1256095 | CVE-2013-6392 | linux-lts-backport-natty (Ubuntu Saucy) | Undecided | Won't Fix | ||
1256095 | CVE-2013-6392 | linux-lts-backport-maverick (Ubuntu Raring) | Undecided | Won't Fix | ||
1256095 | CVE-2013-6392 | linux-lts-backport-natty (Ubuntu Raring) | Undecided | Won't Fix | ||
1256095 | CVE-2013-6392 | linux-lts-backport-maverick (Ubuntu Quantal) | Undecided | Won't Fix | ||
1256095 | CVE-2013-6392 | linux-lts-backport-natty (Ubuntu Quantal) | Undecided | Won't Fix | ||
1256095 | CVE-2013-6392 | linux (Ubuntu Precise) | Low | Invalid | ||
1256095 | CVE-2013-6392 | linux-ec2 (Ubuntu Precise) | Low | Invalid | ||
1256095 | CVE-2013-6392 | linux-fsl-imx51 (Ubuntu Precise) | Low | Invalid | ||
1256095 | CVE-2013-6392 | linux-lts-backport-maverick (Ubuntu Precise) | Undecided | Won't Fix | ||
1256095 | CVE-2013-6392 | linux-lts-backport-natty (Ubuntu Precise) | Undecided | Won't Fix | ||
1256095 | CVE-2013-6392 | linux-mvl-dove (Ubuntu Precise) | Low | Invalid | ||
1256095 | CVE-2013-6392 | linux-ti-omap4 (Ubuntu Precise) | Low | Invalid | ||
1256095 | CVE-2013-6392 | linux-lts-backport-maverick (Ubuntu Lucid) | Undecided | Won't Fix | ||
1256095 | CVE-2013-6392 | linux-lts-backport-natty (Ubuntu Lucid) | Undecided | Won't Fix | ||
1256095 | CVE-2013-6392 | linux-armadaxp (Ubuntu) | Low | Invalid | ||
1256095 | CVE-2013-6392 | linux-armadaxp (Ubuntu Precise) | Low | Invalid | ||
1256095 | CVE-2013-6392 | linux-armadaxp (Ubuntu Trusty) | Low | Invalid | ||
1256095 | CVE-2013-6392 | linux-lts-saucy (Ubuntu) | Low | Invalid | ||
1256095 | CVE-2013-6392 | linux-lts-saucy (Ubuntu Precise) | Low | Invalid | ||
1256095 | CVE-2013-6392 | linux-lts-saucy (Ubuntu Trusty) | Low | Invalid | ||
1256095 | CVE-2013-6392 | linux-lts-quantal (Ubuntu) | Low | Invalid | ||
1256095 | CVE-2013-6392 | linux-lts-quantal (Ubuntu Precise) | Low | Invalid | ||
1256095 | CVE-2013-6392 | linux-lts-quantal (Ubuntu Trusty) | Low | Invalid | ||
1256095 | CVE-2013-6392 | linux-lts-raring (Ubuntu) | Low | Invalid | ||
1256095 | CVE-2013-6392 | linux-lts-raring (Ubuntu Precise) | Low | Won't Fix | ||
1256095 | CVE-2013-6392 | linux-lts-raring (Ubuntu Trusty) | Low | Invalid | ||
1256095 | CVE-2013-6392 | linux-lts-trusty (Ubuntu) | Low | Invalid | ||
1256095 | CVE-2013-6392 | linux-lts-trusty (Ubuntu Precise) | Low | Invalid | ||
1256095 | CVE-2013-6392 | linux-lts-trusty (Ubuntu Trusty) | Low | Invalid | ||
1256095 | CVE-2013-6392 | linux-lts-backport-maverick (Ubuntu Utopic) | Undecided | Won't Fix | ||
1256095 | CVE-2013-6392 | linux-lts-backport-natty (Ubuntu Utopic) | Undecided | Won't Fix | ||
1256095 | CVE-2013-6392 | linux (Ubuntu Vivid) | Low | Invalid | ||
1256095 | CVE-2013-6392 | linux-armadaxp (Ubuntu Vivid) | Low | Invalid | ||
1256095 | CVE-2013-6392 | linux-ec2 (Ubuntu Vivid) | Low | Invalid | ||
1256095 | CVE-2013-6392 | linux-fsl-imx51 (Ubuntu Vivid) | Low | Invalid | ||
1256095 | CVE-2013-6392 | linux-lts-backport-maverick (Ubuntu Vivid) | Undecided | Won't Fix | ||
1256095 | CVE-2013-6392 | linux-lts-backport-natty (Ubuntu Vivid) | Undecided | Won't Fix | ||
1256095 | CVE-2013-6392 | linux-lts-quantal (Ubuntu Vivid) | Low | Invalid | ||
1256095 | CVE-2013-6392 | linux-lts-raring (Ubuntu Vivid) | Low | Invalid | ||
1256095 | CVE-2013-6392 | linux-lts-saucy (Ubuntu Vivid) | Low | Invalid | ||
1256095 | CVE-2013-6392 | linux-lts-trusty (Ubuntu Vivid) | Low | Invalid | ||
1256095 | CVE-2013-6392 | linux-mvl-dove (Ubuntu Vivid) | Low | Invalid | ||
1256095 | CVE-2013-6392 | linux-ti-omap4 (Ubuntu Vivid) | Low | Invalid | ||
1256095 | CVE-2013-6392 | linux-goldfish (Ubuntu) | Low | Invalid | ||
1256095 | CVE-2013-6392 | linux-goldfish (Ubuntu Precise) | Low | Invalid | ||
1256095 | CVE-2013-6392 | linux-goldfish (Ubuntu Trusty) | Low | Invalid | ||
1256095 | CVE-2013-6392 | linux-goldfish (Ubuntu Vivid) | Low | Invalid | ||
1256095 | CVE-2013-6392 | linux-flo (Ubuntu) | Low | New | ||
1256095 | CVE-2013-6392 | linux-flo (Ubuntu Precise) | Low | Invalid | ||
1256095 | CVE-2013-6392 | linux-flo (Ubuntu Trusty) | Low | Invalid | ||
1256095 | CVE-2013-6392 | linux-flo (Ubuntu Vivid) | Low | New | ||
1256095 | CVE-2013-6392 | linux-mako (Ubuntu) | Low | New | ||
1256095 | CVE-2013-6392 | linux-mako (Ubuntu Precise) | Low | Invalid | ||
1256095 | CVE-2013-6392 | linux-mako (Ubuntu Trusty) | Low | Invalid | ||
1256095 | CVE-2013-6392 | linux-mako (Ubuntu Vivid) | Low | New | ||
1256095 | CVE-2013-6392 | linux-lts-utopic (Ubuntu) | Low | Invalid | ||
1256095 | CVE-2013-6392 | linux-lts-utopic (Ubuntu Precise) | Low | Invalid | ||
1256095 | CVE-2013-6392 | linux-lts-utopic (Ubuntu Trusty) | Low | Invalid | ||
1256095 | CVE-2013-6392 | linux-lts-utopic (Ubuntu Vivid) | Low | Invalid | ||
1256095 | CVE-2013-6392 | linux-manta (Ubuntu) | Low | Invalid |
See the
CVE page on Mitre.org
for more details.