CVE-2011-2495

Linux Kernel < 2.6.39.4 - Unauthorized Sensitive I/O Statistics Exposure via /proc/#####/io

Title source: llm
STIX 2.1

Description

fs/proc/base.c in the Linux kernel before 2.6.39.4 does not properly restrict access to /proc/#####/io files, which allows local users to obtain sensitive I/O statistics by polling a file, as demonstrated by discovering the length of another user's password.

Scores

EPSS 0.0048
EPSS Percentile 39.2%

Details

CWE
CWE-264
Status published
Products (4)
linux/linux_kernel 2.6.39 (8 CPE variants)
linux/linux_kernel 2.6.39.1
linux/linux_kernel 2.6.39.2
linux/linux_kernel < 2.6.39.3
Published Jun 13, 2012
Tracked Since Feb 18, 2026