Secunia Logo
 
CVE Reference: CVE-2006-1056
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2006-1056

Description:
The Linux kernel before 2.6.16.9 and the FreeBSD kernel, when running on AMD64 and other 7th and 8th generation AuthenticAMD processors, only save/restore the FOP, FIP, and FDP x87 registers in FXSAVE/FXRSTOR when an exception is pending, which allows one process to determine portions of the state of floating point instructions of other processes, which can be leveraged to obtain sensitive information such as cryptographic keys. NOTE: this is the documented behavior of AMD64 processors, but it is inconsistent with Intel processers in a security-relevant fashion that was not addressed by the kernels.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/25871

UBUNTU
  http://www.ubuntu.com/usn/usn-302-1

SUSE
  http://www.novell.com/linux/security/advisories/2006-05-31.html

ST
  1015966

SAID
  Secunia Advisory: SA21465
  Secunia Advisory: SA21136
  Secunia Advisory: SA21035
  Secunia Advisory: SA20914
  Secunia Advisory: SA20716
  Secunia Advisory: SA20671
  Secunia Advisory: SA19715
  Secunia Advisory: SA19724
  Secunia Advisory: SA20398
  Secunia Advisory: SA21983
  Secunia Advisory: SA22417
  Secunia Advisory: SA22875
  Secunia Advisory: SA22876
  Secunia Advisory: SA19735

REDHAT
  http://www.redhat.com/support/errata/RHSA-2006-0575.html
  http://www.redhat.com/support/errata/RHSA-2006-0437.html
  http://www.redhat.com/support/errata/RHSA-2006-0579.html

OSVDB
  24746
  24807

MLIST
  http://marc.theaimsgroup.com/?l=linux-kernel&m=114548768214478&w=2

MISC
  http://security.freebsd.org/advisories/FreeBSD-SA-06:14-amd.txt

FREEBSD

FEDORA
  http://lwn.net/Alerts/180820/

DEBIAN
  http://www.debian.org/security/2006/dsa-1097
  http://www.debian.org/security/2006/dsa-1103

CONFIRM
  http://support.avaya.com/elmodocs2/security/ASA-2006-200.htm
  http://www.vmware.com/download/esx/esx-254-200610-patch.html
  http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.9
  http://www.vmware.com/download/esx/esx-213-200610-patch.html
  http://kb.vmware.com/kb/2533126
  http://support.avaya.com/elmodocs2/security/ASA-2006-180.htm

BUGTRAQ
  http://www.securityfocus.com/archive/1/archive/1/451417/100/200/threaded
  http://www.securityfocus.com/archive/1/archive/1/451421/100/0/threaded
  http://www.securityfocus.com/archive/1/archive/1/451419/100/200/threaded
  http://www.securityfocus.com/archive/1/archive/1/451404/100/0/threaded

BID
  17600


Return to the previous page.