FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2006-1056

This CVE name corresponds to:

Entered Topic
2006-04-19 FreeBSD -- FPU information disclosure

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2006-1056
Phase Assigned(20060307)

Description

The Linux kernel before 2.6.16.9 and the FreeBSD kernel, when running on AMD64 and other 7th and 8th generation AuthenticAMD processors, only save/restore the FOP, FIP, and FDP x87 registers in FXSAVE/FXRSTOR when an exception is pending, which allows one process to determine portions of the state of floating point instructions of other processes, which can be leveraged to obtain sensitive information such as cryptographic keys. NOTE: this is the documented behavior of AMD64 processors, but it is inconsistent with Intel processers in a security-relevant fashion that was not addressed by the kernels.

References

Source Reference
BUGTRAQ 20060419 FreeBSD Security Advisory FreeBSD-SA-06:14.fpu
BUGTRAQ 20061113 VMSA-2006-0006 - VMware ESX Server 2.5.3 Upgrade Patch 4
BUGTRAQ 20061113 VMSA-2006-0005 - VMware ESX Server 2.5.4 Upgrade Patch 1
BUGTRAQ 20061113 VMSA-2006-0007 - VMware ESX Server 2.1.3 Upgrade Patch 2
BUGTRAQ 20061113 VMSA-2006-0009 - VMware ESX Server 3.0.0 AMD fxsave/restore issue
CONFIRM http://support.avaya.com/elmodocs2/security/ASA-2006-180.htm
CONFIRM http://support.avaya.com/elmodocs2/security/ASA-2006-200.htm
CONFIRM http://kb.vmware.com/kb/2533126
CONFIRM http://www.vmware.com/download/esx/esx-213-200610-patch.html
CONFIRM http://www.vmware.com/download/esx/esx-254-200610-patch.html
DEBIAN DSA-1097
DEBIAN DSA-1103
FEDORA FEDORA-2006-423
FREEBSD FreeBSD-SA-06:14
MISC http://security.freebsd.org/advisories/FreeBSD-SA-06:14-amd.txt
CONFIRM http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.9
CONFIRM https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=187910
CONFIRM https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=187911
MLIST [linux-kernel] 20060419 RE: Linux 2.6.16.9
REDHAT RHSA-2006:0579
REDHAT RHSA-2006:0437
REDHAT RHSA-2006:0575
SUSE SUSE-SA:2006:028
SUSE SUSE-SU-2014:0446
UBUNTU USN-302-1
BID 17600
OVAL oval:org.mitre.oval:def:9995
VUPEN ADV-2006-1426
VUPEN ADV-2006-2554
VUPEN ADV-2006-4353
VUPEN ADV-2006-4502
VUPEN ADV-2006-1475
OSVDB 24807
OSVDB 24746
SECTRACK 1015966
SECUNIA 19724
SECUNIA 19715
SECUNIA 20671
SECUNIA 20716
SECUNIA 20914
SECUNIA 21035
SECUNIA 21136
SECUNIA 21465
SECUNIA 20398
SECUNIA 21983
SECUNIA 22417
SECUNIA 22875
SECUNIA 22876
SECUNIA 19735
XF amd-fpu-information-disclosure(25871)