Description: | The report API in the crypto user configuration API in the Linux kernel through 3.8.2 uses an incorrect C library function for copying strings, which allows local users to obtain sensitive information from kernel stack memory by leveraging the CAP_NET_ADMIN capability. Mathias Krause discovered a memory leak in the Linux kernel's crypto report API. A local user with CAP_NET_ADMIN could exploit this leak to examine some of the kernel's stack memory.
|