The tipc_nl_compat_link_dump function in net/tipc/netlink_compat.c in the Linux kernel through 4.6.3 does not properly copy a certain string, which allows local users to obtain sensitive information from kernel stack memory by reading a Netlink message.
References
Configurations
History
No history.
Information
Published : 2016-06-27 10:59
Updated : 2024-02-04 18:53
NVD link : CVE-2016-5243
Mitre link : CVE-2016-5243
CVE.ORG link : CVE-2016-5243
JSON object : View
Products Affected
linux
- linux_kernel
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor