The atyfb_ioctl function in drivers/video/fbdev/aty/atyfb_base.c in the Linux kernel through 4.12.10 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory by reading locations associated with padding bytes.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://marc.info/?l=linux-kernel&m=150453196710422&w=2 | mailing list third party advisory patch |
https://usn.ubuntu.com/3583-2/ | vendor advisory |
http://www.debian.org/security/2017/dsa-3981 | vendor advisory |
https://github.com/torvalds/linux/pull/441 | issue tracking third party advisory patch |
https://usn.ubuntu.com/3583-1/ | vendor advisory |
http://www.securityfocus.com/bid/100634 | vdb entry |
https://marc.info/?l=linux-kernel&m=150401461613306&w=2 | mailing list third party advisory patch |