The atyfb_ioctl function in drivers/video/fbdev/aty/atyfb_base.c in the Linux kernel up to and including 4.12.10 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory by reading locations associated with padding bytes.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
linux linux kernel |