Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:13144
HistoryJan 15, 2019 - 9:26 a.m.

Information Disclosure

2019-01-1509:26:26
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
19

EPSS

0.001

Percentile

40.7%

Linux kernel that is built with CONFIG_POSIX_TIMERES and CONFIG_CHECKPOINT_RESTORE is vulnerable to information disclosure. An out-of-bounds access in the show_timer function in the timer_create syscall implementation in kernel/time/posix-timers.c allows userspace applications to read arbitrary kernel memory containing confidential information. This is due to an improper validation of the sigevent->sigev_notify field when /proc/$PID/timers is read.