The compat_get_timex function in kernel/compat.c in the Linux kernel before 4.16.9 allows local users to obtain sensitive information from kernel memory via adjtimex.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://usn.ubuntu.com/3695-1/ | third party advisory vendor advisory |
https://usn.ubuntu.com/3695-2/ | third party advisory vendor advisory |
https://bugs.chromium.org/p/project-zero/issues/detail?id=1574 | issue tracking exploit third party advisory |
https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.16.9 | release notes vendor advisory |
http://www.securityfocus.com/bid/104292 | vdb entry third party advisory |
https://usn.ubuntu.com/3697-1/ | third party advisory vendor advisory |
https://github.com/torvalds/linux/commit/0a0b98734479aa5b3c671d5190e86273372cab95 | third party advisory patch |
https://usn.ubuntu.com/3697-2/ | third party advisory vendor advisory |
https://www.exploit-db.com/exploits/46208/ | exploit vdb entry third party advisory |
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=0a0b98734479aa5b3c671d5190e86273372cab95 | patch vendor advisory |