Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-4482

Опубликовано: 23 мая 2016
Источник: debian
EPSS Низкий

Описание

The proc_connectinfo function in drivers/usb/core/devio.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via a crafted USBDEVFS_CONNECTINFO ioctl call.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
linuxfixed4.5.5-1package

Примечания

  • http://www.spinics.net/lists/linux-usb/msg140243.html

  • https://www.openwall.com/lists/oss-security/2016/05/04/2

  • Fixed by: https://github.com/torvalds/linux/commit/681fef8380eb818c0b845fca5d2ab1dcbab114ee

EPSS

Процентиль: 3%
0.00018
Низкий

Связанные уязвимости

CVSS3: 6.2
ubuntu
около 9 лет назад

The proc_connectinfo function in drivers/usb/core/devio.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via a crafted USBDEVFS_CONNECTINFO ioctl call.

redhat
около 9 лет назад

The proc_connectinfo function in drivers/usb/core/devio.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via a crafted USBDEVFS_CONNECTINFO ioctl call.

CVSS3: 6.2
nvd
около 9 лет назад

The proc_connectinfo function in drivers/usb/core/devio.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via a crafted USBDEVFS_CONNECTINFO ioctl call.

CVSS3: 6.2
github
около 3 лет назад

The proc_connectinfo function in drivers/usb/core/devio.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via a crafted USBDEVFS_CONNECTINFO ioctl call.

oracle-oval
больше 8 лет назад

ELSA-2017-3515: Unbreakable Enterprise kernel security update (IMPORTANT)

EPSS

Процентиль: 3%
0.00018
Низкий