Back

HIGH

kernel: Information leak in llc module

Published May 23, 2016

Description

The llc_cmsg_rcv function in net/llc/af_llc.c in the Linux kernel before 4.5.5 does not initialize a certain data structure, which allows attackers to obtain sensitive information from kernel stack memory by reading a message.

Affected products

Remediation

Red Hat statement

This issue does not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 5, 6, 7 and MRG-2 as the related code with the flaw is not present in the products listed.

Metrics

References (25)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 23, 2016
Updated Aug 6, 2024
Reserved May 4, 2016
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date May 4, 2016