Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:18248
HistoryMay 02, 2019 - 6:36 a.m.

Stack-based Buffer Overflow

2019-05-0206:36:13
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7

0.0004 Low

EPSS

Percentile

5.1%

Linux kernel is vulnerable to stack-based buffer overflow vulnerability. The vulnerability exists in the sg_ioctl function in drivers/scsi/sg.c in the Linux kernel. A local user could cause a a denial of service condition or possibly have unspecified other impacts via a large command size in an SG_NEXT_CMD_LEN ioctl call, leading to out-of-bounds write access in the sg_write function.

References