Description
net/packet/af_packet.c in the Linux kernel before 2.6.37-rc2 does not properly initialize certain structure members, which allows local users to obtain potentially sensitive information from kernel stack memory by leveraging the CAP_NET_RAW capability to read copies of the applicable structures.
References (23)
... and 3 more
Scores
EPSS
0.0006
EPSS Percentile
17.8%
Details
CWE
CWE-909
Status
published
Products (10)
debian/debian_linux
5.0
linux/linux_kernel
2.6.37 (2 CPE variants)
linux/linux_kernel
< 2.6.37
opensuse/opensuse
11.2
opensuse/opensuse
11.3
suse/linux_enterprise_desktop
10 sp3
suse/linux_enterprise_real_time_extension
11 sp1
suse/linux_enterprise_server
9
suse/linux_enterprise_server
10 sp3
suse/linux_enterprise_software_development_kit
10 sp3
Published
Jan 03, 2011
Tracked Since
Feb 18, 2026