2013-11-30 03:55:04 2014-03-05 19:29:07

The genlock_dev_ioctl function in genlock.c in the Genlock driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not properly initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via a crafted GENLOCK_IOC_EXPORT ioctl call.

Vector

LOCAL

Complexity

LOW

Authentication

NONE

Confidentiality

COMPLETE

Integrity

NONE

Availability

NONE
Codeaurora Android-msm 3.13 (not an official CPE) Codeaurora Android-msm 3.4.75 (not an official CPE) Codeaurora Android-msm 3.4.72 (not an official CPE) Codeaurora Android-msm 3.4.73 (not an official CPE) Codeaurora Android-msm 3.4.78 (not an official CPE) Codeaurora Android-msm 3.10.28 (not an official CPE) Codeaurora Android-msm 3.4.76 (not an official CPE) Codeaurora Android-msm 3.4.79 (not an official CPE) Codeaurora Android-msm 3.4.74 (not an official CPE) Codeaurora Android-msm 3.4.77 (not an official CPE) Codeaurora Android-msm 3.10.24 (not an official CPE) Codeaurora Android-msm 3.10.27 (not an official CPE) Codeaurora Android-msm 3.12.8 (not an official CPE) Codeaurora Android-msm 3.10.26 (not an official CPE) Codeaurora Android-msm 3.10.29 (not an official CPE) Codeaurora Android-msm 3.12.6 (not an official CPE) Codeaurora Android-msm 3.12.9 (not an official CPE) Codeaurora Android-msm 3.10.23 (not an official CPE) Codeaurora Android-msm 3.10.22 (not an official CPE) Codeaurora Android-msm 3.12.4 (not an official CPE) Codeaurora Android-msm 3.12.7 (not an official CPE) Codeaurora Android-msm 3.10.25 (not an official CPE) Codeaurora Android-msm 3.13 Rc2 (not an official CPE) Codeaurora Android-msm 3.13 Rc7 (not an official CPE) Codeaurora Android-msm 3.13 Rc4 (not an official CPE) Codeaurora Android-msm 3.13 Rc1 (not an official CPE) Codeaurora Android-msm 3.13 Rc6 (not an official CPE) Codeaurora Android-msm 3.12.3 (not an official CPE) Codeaurora Android-msm 3.12.5 (not an official CPE) Codeaurora Android-msm 3.13 Rc8 (not an official CPE) Codeaurora Android-msm 3.13 Rc5 (not an official CPE) Codeaurora Android-msm 3.2.54 (not an official CPE) Codeaurora Android-msm 3.12.10 (not an official CPE) Codeaurora Android-msm 3.13.1 (not an official CPE) Codeaurora Android-msm 3.13.2 (not an official CPE) Codeaurora Android-msm 3.13 Rc3 (not an official CPE) Codeaurora Android-msm 3.14 Rc2 (not an official CPE) Codeaurora Android-msm 3.14 Rc1 (not an official CPE)