Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:24306
HistoryApr 10, 2020 - 12:52 a.m.

Information Disclosure

2020-04-1000:52:11
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11

0.0004 Low

EPSS

Percentile

10.3%

kernel is vulnerable to information disclosure. The cxgb_extension_ioctl function in drivers/net/cxgb3/cxgb3_main.c does not properly initialize a certain structure member, which allows local users to obtain potentially confidential information from kernel stack memory via a CHELSIO_GET_QSET_NUM ioctl call.

References