Lucene search

K
cvelistMitreCVELIST:CVE-2016-4482
HistoryMay 23, 2016 - 10:00 a.m.

CVE-2016-4482

2016-05-2310:00:00
mitre
www.cve.org
1

6.2 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

48.9%

The proc_connectinfo function in drivers/usb/core/devio.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via a crafted USBDEVFS_CONNECTINFO ioctl call.

References