Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vv7x-5v76-w79j

Опубликовано: 19 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 5.5

Описание

The Linux waitid() implementation translates a FreeBSD siginfo_t struct into a stack-declared Linux siginfo_t. It did not first zero the stack struct.

An unprivileged user may observe 104 bytes of uninitialized kernel stack data, which may contain sensitive information.

The Linux waitid() implementation translates a FreeBSD siginfo_t struct into a stack-declared Linux siginfo_t. It did not first zero the stack struct.

An unprivileged user may observe 104 bytes of uninitialized kernel stack data, which may contain sensitive information.

EPSS

Процентиль: 2%
0.00113
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-908

Связанные уязвимости

CVSS3: 5.5
nvd
около 1 месяца назад

The Linux waitid() implementation translates a FreeBSD siginfo_t struct into a stack-declared Linux siginfo_t. It did not first zero the stack struct. An unprivileged user may observe 104 bytes of uninitialized kernel stack data, which may contain sensitive information.

CVSS3: 3.3
fstec
6 месяцев назад

Уязвимость реализации системного вызова waitid() слоя совместимости Linuxulator ядра операционных систем FreeBSD, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 2%
0.00113
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-908