Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x8jc-52cg-pxpq

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The llc_ui_recvmsg function in net/llc/af_llc.c in the Linux kernel before 3.9-rc7 does not initialize a certain length variable, which allows local users to obtain sensitive information from kernel stack memory via a crafted recvmsg or recvfrom system call.

The llc_ui_recvmsg function in net/llc/af_llc.c in the Linux kernel before 3.9-rc7 does not initialize a certain length variable, which allows local users to obtain sensitive information from kernel stack memory via a crafted recvmsg or recvfrom system call.

EPSS

Процентиль: 24%
0.00077
Низкий

Дефекты

CWE-200

Связанные уязвимости

ubuntu
больше 12 лет назад

The llc_ui_recvmsg function in net/llc/af_llc.c in the Linux kernel before 3.9-rc7 does not initialize a certain length variable, which allows local users to obtain sensitive information from kernel stack memory via a crafted recvmsg or recvfrom system call.

redhat
больше 12 лет назад

The llc_ui_recvmsg function in net/llc/af_llc.c in the Linux kernel before 3.9-rc7 does not initialize a certain length variable, which allows local users to obtain sensitive information from kernel stack memory via a crafted recvmsg or recvfrom system call.

nvd
больше 12 лет назад

The llc_ui_recvmsg function in net/llc/af_llc.c in the Linux kernel before 3.9-rc7 does not initialize a certain length variable, which allows local users to obtain sensitive information from kernel stack memory via a crafted recvmsg or recvfrom system call.

debian
больше 12 лет назад

The llc_ui_recvmsg function in net/llc/af_llc.c in the Linux kernel be ...

oracle-oval
около 12 лет назад

ELSA-2013-1034: kernel security and bug fix update (LOW)

EPSS

Процентиль: 24%
0.00077
Низкий

Дефекты

CWE-200