CVE-2012-6546

Linux Kernel < 3.6 - Information Exposure via Uninitialized ATM Structures

Title source: llm
STIX 2.1

Description

The ATM implementation in the Linux kernel before 3.6 does not initialize certain structures, which allows local users to obtain sensitive information from kernel stack memory via a crafted application.

Scores

EPSS 0.0040
EPSS Percentile 31.8%

Details

CWE
CWE-200
Status published
Products (44)
linux/linux_kernel 3.0 rc1 (7 CPE variants)
linux/linux_kernel 3.0.1
linux/linux_kernel 3.0.2
linux/linux_kernel 3.0.3
linux/linux_kernel 3.0.4
linux/linux_kernel 3.0.5
linux/linux_kernel 3.0.6
linux/linux_kernel 3.0.7
linux/linux_kernel 3.0.8
linux/linux_kernel 3.0.9
... and 34 more
Published Mar 15, 2013
Tracked Since Feb 18, 2026