Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Multiple Vendor KernFS LSEEK Local Kernel Memory Disclosure Vulnerability

The 'kernfs' filesystem in both NetBSD and OpenBSD is prone to a kernel memory disclosure vulnerability. This issue arises due to insufficient sanitization of user-supplied arguments passed to the 'lseek()' system call.

An attacker may use information disclosed through this attack to launch other attacks against a computer and potentially to aid in a complete compromise.

Note that OpenBSD has completely removed kernfs since OpenBSD 3.8; version 3.7 had kernfs support disabled in their GENERIC kernel, and has never mounted the kernfs filesystem by default.







 

Privacy Statement
Copyright 2009, SecurityFocus