The tty_set_termios_ldisc function in drivers/tty/tty_ldisc.c in the Linux kernel before 4.5 allows local users to obtain sensitive information from kernel memory by reading a tty data structure.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://source.android.com/security/bulletin/2016-11-01.html | third party advisory |
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=dd42bf1197144ede075a9d4793123f7689e164bc | patch vendor advisory |
https://github.com/torvalds/linux/commit/dd42bf1197144ede075a9d4793123f7689e164bc | patch vendor advisory |
http://www.securityfocus.com/bid/94138 | vdb entry |