The copy_to_user_auth function in net/xfrm/xfrm_user.c in the Linux kernel before 3.6 uses an incorrect C library function for copying a string, which allows local users to obtain sensitive information from kernel heap memory by leveraging the CAP_NET_ADMIN capability. Per https://access.redhat.com/security/cve/CVE-2012-6538
"This issue affects the versions of Linux kernel as shipped with Red Hat
Enterprise Linux 6 . Future kernel updates for Red Hat Enterprise Linux 6 may
address this issue."
Publication date: Sat, 16 Mar 2013 01:55:00 +0000