Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-4485

Опубликовано: 04 мая 2016
Источник: redhat
CVSS2: 2.1
EPSS Низкий

Описание

The llc_cmsg_rcv function in net/llc/af_llc.c in the Linux kernel before 4.5.5 does not initialize a certain data structure, which allows attackers to obtain sensitive information from kernel stack memory by reading a message.

An information leak vulnerability in [llc] module was found in "net/llc/af_llc.c". The stack object "info" has a total size of 12 bytes. Its last byte is padding which is not initialized and leaked via put_cmsg().

Отчет

This issue does not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 5, 6, 7 and MRG-2 as the related code with the flaw is not present in the products listed.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kernelNot affected
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernelNot affected
Red Hat Enterprise Linux 7kernel-rtNot affected
Red Hat Enterprise MRG 2realtime-kernelNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1333309kernel: Information leak in llc module

EPSS

Процентиль: 66%
0.00509
Низкий

2.1 Low

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 10 лет назад

The llc_cmsg_rcv function in net/llc/af_llc.c in the Linux kernel before 4.5.5 does not initialize a certain data structure, which allows attackers to obtain sensitive information from kernel stack memory by reading a message.

CVSS3: 7.5
nvd
почти 10 лет назад

The llc_cmsg_rcv function in net/llc/af_llc.c in the Linux kernel before 4.5.5 does not initialize a certain data structure, which allows attackers to obtain sensitive information from kernel stack memory by reading a message.

CVSS3: 7.5
debian
почти 10 лет назад

The llc_cmsg_rcv function in net/llc/af_llc.c in the Linux kernel befo ...

CVSS3: 7.5
github
почти 4 года назад

The llc_cmsg_rcv function in net/llc/af_llc.c in the Linux kernel before 4.5.5 does not initialize a certain data structure, which allows attackers to obtain sensitive information from kernel stack memory by reading a message.

oracle-oval
около 9 лет назад

ELSA-2017-3515: Unbreakable Enterprise kernel security update (IMPORTANT)

EPSS

Процентиль: 66%
0.00509
Низкий

2.1 Low

CVSS2