Missing release of memory after effective lifetime in Linux kernel - CVE-2003-0984

 

Missing release of memory after effective lifetime in Linux kernel - CVE-2003-0984

Published: January 5, 2004 / Updated: October 11, 2017


Vulnerability identifier: #VU95659
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2003-0984
CWE-ID: CWE-401
Exploitation vector: Local access
Exploit availability: No public exploit available
Vendor: Linux Foundation
Affected software:
Linux kernel

Detailed vulnerability description

The vulnerability allows a local user to read and manipulate data.

Real time clock (RTC) routines in Linux kernel 2.4.23 and earlier do not properly initialize their structures, which could leak kernel data to user space.


How to mitigate CVE-2003-0984

Install update from vendor's repository.

Sources