CVE-2016-4485
The llc_cmsg_rcv function in net/llc/af_llc.c in the Linux kernel before 4.5.5 does not initialize a certain data struct
The llc_cmsg_rcv function in net/llc/af_llc.c in the Linux kernel before 4.5.5 does not initialize a certain data structure, which allows attackers to obtain sensitive information from kernel stack memory by reading a message.
HIGH · CVSS 7.5
EPSS 0.00774
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0