Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:11401
HistoryJan 15, 2019 - 9:01 a.m.

Sensitive Information Leakage

2019-01-1509:01:27
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13

0.0004 Low

EPSS

Percentile

10.1%

The kernel-rt packages is susceptible to denial of service (DoS). The attack is possible because it does not make sure the addr_len value to get initialized with the associated data structure, allowing a local unauthorized user to do the recvmsg, recvfrom, and recvmmsg system calls to leak kernel stack memory to user space.

References