drivers/scsi/stex.c in the Linux kernel through 5.19.9 allows local users to obtain sensitive information from kernel memory because stex_queuecommand_lck lacks a memset for the PASSTHRU_CMD case.
                
            References
                    Configurations
                    Configuration 1 (hide)
                                
                                
  | 
                        
Configuration 2 (hide)
                                
                                
  | 
                        
Configuration 3 (hide)
                                
                                
  | 
                        
Information
                Published : 2022-09-17 22:15
Updated : 2023-02-23 07:41
NVD link : CVE-2022-40768
Mitre link : CVE-2022-40768
JSON object : View
CWE
                
                    
                        
                        CWE-668
                        
            Exposure of Resource to Wrong Sphere
Products Affected
                fedoraproject
- fedora
 
debian
- debian_linux
 
linux
- linux_kernel
 


