CVE-2014-1445

Linux Kernel < 3.11.7 - Information Disclosure via wanxl_ioctl

Title source: llm
STIX 2.1

Description

The wanxl_ioctl function in drivers/net/wan/wanxl.c in the Linux kernel before 3.11.7 does not properly initialize a certain data structure, which allows local users to obtain sensitive information from kernel memory via an ioctl call.

References (9)

Core 9
Core References
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2129-1
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2128-1
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=1053613
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/90444
Patch mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2014/01/15/3
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/64953

Scores

EPSS 0.0041
EPSS Percentile 34.1%

Details

CWE
CWE-399
Status published
Products (7)
linux/linux_kernel 3.11
linux/linux_kernel 3.11.1
linux/linux_kernel 3.11.2
linux/linux_kernel 3.11.3
linux/linux_kernel 3.11.4
linux/linux_kernel 3.11.5
linux/linux_kernel < 3.11.6
Published Jan 18, 2014
Tracked Since Feb 18, 2026