Fixed                
                
            
            
                
                    Created: Jan 15, 2014   
                                            Updated: Dec 3, 2018                                    
                
                    
                                    
             
         
        
            
            
                                    
                        Resolved Date: Feb 9, 2014                    
                
                
                                    
                        Found In Version: 6.0.0.3                    
                
                                    
                        Fix Version: 6.0.0.3                    
                
                                        
                            Severity: Standard                        
                    
                                        
                            Applicable for: Wind River Linux 6                        
                    
                                    
                        Component/s: Kernel                    
                
                
                             
         
                        
                The Linux kernel before 3.12.4 updates certain length values before ensuring that associated data structures have been initialized, which allows local users to obtain sensitive information from kernel stack memory via a (1) recvfrom, (2) recvmmsg, or (3) recvmsg system call, related to net/ipv4/ping.c, net/ipv4/raw.c, net/ipv4/udp.c, net/ipv6/raw.c, and net/ipv6/udp.c.
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-7263