The tipc_nl_compat_link_dump function in net/tipc/netlink_compat.c in the Linux kernel through 4.6.3 does not properly copy a certain string, which allows local users to obtain sensitive information from kernel stack memory by reading a Netlink message.
References
Configurations
Information
Published : 2016-06-27 03:59
Updated : 2016-11-28 12:23
NVD link : CVE-2016-5243
Mitre link : CVE-2016-5243
JSON object : View
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
linux
- linux_kernel