CVE-2021-34693

Related Vulnerabilities: CVE-2021-34693  

net/can/bcm.c in the Linux kernel through 5.12.10 allows local users to obtain sensitive information from kernel stack memory because parts of a data structure are uninitialized.

Description

The MITRE CVE dictionary describes this issue as:

net/can/bcm.c in the Linux kernel through 5.12.10 allows local users to obtain sensitive information from kernel stack memory because parts of a data structure are uninitialized.

Additional Information

  • Bugzilla 1972265: CVE-2021-34693 kernel: allows local users to obtain sensitive information from stack memory because of uninitialized data structure in net/can/bcm.c
  • CWE-665->CWE-200: Improper Initialization leads to Exposure of Sensitive Information to an Unauthorized Actor
  • FAQ: Frequently asked questions about CVE-2021-34693