The ext3 code in Linux 2.4.x before 2.4.26 does not properly initialize journal descriptor blocks, which causes an information leak in which in-memory data is written to the device for the ext3 file system, which allows privileged users to obtain portions of kernel memory by reading the raw device.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Linux_kernel | Linux | 2.4.0 (including) | 2.4.0 (including) |
Red Hat Enterprise Linux 3 | RedHat | kernel-0:2.4.21-27.0.4.EL | * |
Red Hat Enterprise Linux AS (Advanced Server) version 2.1 | RedHat | * | |
Red Hat Enterprise Linux AS (Advanced Server) version 2.1 | RedHat | * | |
Red Hat Enterprise Linux ES version 2.1 | RedHat | * | |
Red Hat Enterprise Linux WS version 2.1 | RedHat | * | |
Red Hat Linux 9 | RedHat | * | |
Red Hat Linux Advanced Workstation 2.1 | RedHat | * | |
Kernel-source-2.4.27 | Ubuntu | dapper | * |
Kernel-source-2.4.27 | Ubuntu | edgy | * |