CVE-2004-0685

Linux Kernel - Information Disclosure via Uninitialized USB Driver Memory

Title source: llm
STIX 2.1

Description

Certain USB drivers in the Linux 2.4 kernel use the copy_to_user function on uninitialized structures, which could allow local users to obtain sensitive information by reading memory that was not cleared from previous usage.

References (19)

Core 19
Core References
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/20163
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/981134
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/16931
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2006/dsa-1082
Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/10892
Issue Tracking vendor-advisory x_refsource_fedora
https://bugzilla.fedora.us/show_bug.cgi?id=2336
Patch, Vendor Advisory vendor-advisory x_refsource_gentoo
http://www.gentoo.org/security/en/glsa/glsa-200408-24.xml
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2006/dsa-1070
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/20162
Various Sources vendor-advisory x_refsource_trustix
http://www.trustix.net/errata/2004/0041/
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2006/dsa-1067
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2006/dsa-1069
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2004-505.html
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10665
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/20202
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2004-504.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/20338

Scores

EPSS 0.0048
EPSS Percentile 38.9%

Details

Status published
Products (30)
linux/linux_kernel 2.2.0
linux/linux_kernel 2.2.1
linux/linux_kernel 2.2.2
linux/linux_kernel 2.2.3
linux/linux_kernel 2.2.4
linux/linux_kernel 2.2.5
linux/linux_kernel 2.2.6
linux/linux_kernel 2.2.7
linux/linux_kernel 2.2.8
linux/linux_kernel 2.2.9
... and 20 more
Published Dec 23, 2004
Tracked Since Feb 18, 2026