CVE-2009-1192

Publication date 24 April 2009

Last updated 24 July 2024


Ubuntu priority

The (1) agp_generic_alloc_page and (2) agp_generic_alloc_pages functions in drivers/char/agp/generic.c in the agp subsystem in the Linux kernel before 2.6.30-rc3 do not zero out pages that may later be available to a user-space process, which allows local users to obtain sensitive information by reading these pages.

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
linux 9.04 jaunty
Fixed 2.6.28-13.45
8.10 intrepid
Fixed 2.6.27-14.35
8.04 LTS hardy
Fixed 2.6.24-24.55
6.06 LTS dapper Not in release
linux-source-2.6.15 9.04 jaunty Not in release
8.10 intrepid Not in release
8.04 LTS hardy Not in release
6.06 LTS dapper
Fixed 2.6.15-54.77

References

Related Ubuntu Security Notices (USN)

    • USN-793-1
    • Linux kernel vulnerabilities
    • 2 July 2009

Other references