Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:23915
HistoryApr 10, 2020 - 12:40 a.m.

Information Disclosure

2020-04-1000:40:00
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12

0.0004 Low

EPSS

Percentile

10.1%

The kernel-rt is vulnerable to Information Disclosure. Kees Cook and Steve Beattie discovered a race condition in the /proc code in the Linux kernel. This could lead to information in the “/proc/[pid]/maps” and “/proc/[pid]/smaps” files being leaked to users (who would otherwise not have access to this information) during ELF loading. This could help a local attacker bypass the ASLR security feature.

References