Information Leak in Linux Kernel Network Interface
CVE-2016-4486

3.3LOW

Summary

The rtnl_fill_link_ifmap function within the Linux kernel prior to version 4.5.5 is affected by an uninitialized data structure, which poses a risk by allowing local users to access sensitive information from the kernel stack memory via Netlink messages. This vulnerability can lead to unauthorized exposure of critical data, necessitating prompt evaluation and mitigation strategies for users of affected Linux kernel versions.

References

CVSS V3.1

Score:
3.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.