In the Linux kernel, the following vulnerability has been resolved: xfrm_user: fix info leak in build_report() struct xfrm_user_report is a __u8 proto field followed by a struct xfrm_selector which means there is three "empty" bytes of padding, but the padding is never zeroed before copying to userspace. Fix that up by zeroing the structure before setting individual member variables.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
| Attack Vector | LOCAL |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | LOW |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | NONE |
| Integrity Impact | NONE |
| Availability Impact | HIGH |
| Source | Type | Description |
|---|---|---|
| [email protected] | Primary |
en
CWE-401
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| linux | linux_kernel | * | <built-in method update of dict object at 0x7d242450afc0> | Operating System |
| linux | linux_kernel | * | <built-in method update of dict object at 0x7d23afb19640> | Operating System |
| linux | linux_kernel | * | <built-in method update of dict object at 0x7d24245082c0> | Operating System |
| linux | linux_kernel | * | <built-in method update of dict object at 0x7d23afb1ba00> | Operating System |
| linux | linux_kernel | * | <built-in method update of dict object at 0x7d2424509300> | Operating System |
| linux | linux_kernel | * | <built-in method update of dict object at 0x7d2424508900> | Operating System |
| linux | linux_kernel | * | <built-in method update of dict object at 0x7d24245085c0> | Operating System |
| linux | linux_kernel | 2.6.19 | <built-in method update of dict object at 0x7d242450b480> | Operating System |
| linux | linux_kernel | 7.0 | <built-in method update of dict object at 0x7d23afb18f80> | Operating System |
| linux | linux_kernel | 7.0 | <built-in method update of dict object at 0x7d242450a900> | Operating System |
| linux | linux_kernel | 7.0 | <built-in method update of dict object at 0x7d239fbe8ec0> | Operating System |
| linux | linux_kernel | 7.0 | <built-in method update of dict object at 0x7d2424509380> | Operating System |
| linux | linux_kernel | 7.0 | <built-in method update of dict object at 0x7d2424509400> | Operating System |
| linux | linux_kernel | 7.0 | <built-in method update of dict object at 0x7d23a59c8cc0> | Operating System |
| linux | linux_kernel | 7.0 | <built-in method update of dict object at 0x7d23a59c83c0> | Operating System |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:2.6.19:-:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:7.0:rc5:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:7.0:rc6:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:7.0:rc7:*:*:*:*:*:* |