Linux Kernel Improper Input Validation Vulnerability
v6k 및 v7 ARM 플랫폼에서 Linux kernel 3.5.5 이전 버전의 (1) get_user 및 (2) put_user API 함수는 특정 주소를 검증하지 않으므로, 공격자가 조작된 애플리케이션을 통해 임의의 커널 메모리 위치에 있는 내용을 읽거나 수정할 수 있으며, 이는 2013년 10월과 11월 Android 기기를 대상으로 실제로 악용되었다.
v6k 및 v7 ARM 플랫폼에서 Linux kernel 3.5.5 이전 버전의 (1) get_user 및 (2) put_user API 함수는 특정 주소를 검증하지 않으므로, 공격자가 조작된 애플리케이션을 통해 임의의 커널 메모리 위치에 있는 내용을 읽거나 수정할 수 있으며, 이는 2013년 10월과 11월 Android 기기를 대상으로 실제로 악용되었다.
한국어 설명은 영문 원문을 기준으로 제공됩니다. 제품명·버전·보안 식별자는 아래 원문과 함께 확인할 수 있습니다.
영문 원문 보기
The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not validate certain addresses, which allows attackers to read or modify the contents of arbitrary kernel memory locations via a crafted application, as exploited in the wild against Android devices in October and November 2013.
영향 제품·버전
제품 Linux Kernel
영향 버전 Linux Kernel < 3.2.54, >= 3.3 < 3.4.12, >= 3.5 < 3.5.5