CVE-2011-2909

Publication date 6 October 2011

Last updated 24 July 2024


Ubuntu priority

The do_devinfo_ioctl function in drivers/staging/comedi/comedi_fops.c in the Linux kernel before 3.1 allows local users to obtain sensitive information from kernel memory via a copy of a short string.

From the Ubuntu Security Team

Vasiliy Kulikov discovered that the Comedi driver did not correctly clear memory. A local attacker could exploit this to read kernel stack memory, leading to a loss of privacy.

Status

Package Ubuntu Release Status
linux 11.10 oneiric
Not affected
11.04 natty
Fixed 2.6.38-13.52
10.10 maverick
Fixed 2.6.35-30.61
10.04 LTS lucid
Fixed 2.6.32-34.73
8.04 LTS hardy
Not affected
linux-ec2 11.10 oneiric Not in release
11.04 natty Not in release
10.10 maverick Ignored end of life
10.04 LTS lucid
Fixed 2.6.32-318.37
8.04 LTS hardy Not in release
linux-fsl-imx51 11.10 oneiric Not in release
11.04 natty Not in release
10.10 maverick Not in release
10.04 LTS lucid
Fixed 2.6.31-611.29
8.04 LTS hardy Not in release
linux-lts-backport-maverick 11.10 oneiric Not in release
11.04 natty Not in release
10.10 maverick Not in release
10.04 LTS lucid
Fixed 2.6.35-30.61~lucid1
8.04 LTS hardy Not in release
linux-lts-backport-natty 11.10 oneiric Not in release
11.04 natty Not in release
10.10 maverick Not in release
10.04 LTS lucid
Fixed 2.6.38-13.52~lucid1
8.04 LTS hardy Not in release
linux-lts-backport-oneiric 11.10 oneiric Not in release
11.04 natty Not in release
10.10 maverick Not in release
10.04 LTS lucid
Not affected
8.04 LTS hardy Not in release
linux-mvl-dove 11.10 oneiric Not in release
11.04 natty Not in release
10.10 maverick
Fixed 2.6.32-418.35
10.04 LTS lucid
Fixed 2.6.32-218.35
8.04 LTS hardy Not in release
linux-ti-omap4 11.10 oneiric
Not affected
11.04 natty
Fixed 2.6.38-1209.17
10.10 maverick
Fixed 2.6.35-903.26
10.04 LTS lucid Not in release
8.04 LTS hardy Not in release

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
linux

References

Related Ubuntu Security Notices (USN)

    • USN-1208-1
    • Linux kernel (Marvel DOVE) vulnerabilities
    • 14 September 2011
    • USN-1241-1
    • Linux kernel (i.MX51) vulnerabilities
    • 25 October 2011
    • USN-1243-1
    • Linux kernel vulnerabilities
    • 25 October 2011
    • USN-1281-1
    • Linux (OMAP4) vulnerabilities
    • 24 November 2011
    • USN-1285-1
    • Linux kernel vulnerabilities
    • 29 November 2011
    • USN-1203-1
    • Linux kernel (Marvel DOVE) vulnerabilities
    • 13 September 2011
    • USN-1279-1
    • Linux (Natty backport) vulnerabilities
    • 24 November 2011
    • USN-1218-1
    • Linux kernel vulnerabilities
    • 29 September 2011
    • USN-1244-1
    • Linux kernel (OMAP4) vulnerabilities
    • 25 October 2011
    • USN-1242-1
    • Linux kernel (Maverick backport) vulnerabilities
    • 25 October 2011
    • USN-1216-1
    • Linux kernel (EC2) vulnerabilities
    • 26 September 2011

Other references