The sys_get_thread_area function in process.c in Linux 2...
Low severity
Unreviewed
Published
May 1, 2022
to the GitHub Advisory Database
•
Updated Jan 30, 2023
Description
Published by the National Vulnerability Database
Oct 21, 2005
Published to the GitHub Advisory Database
May 1, 2022
Last updated
Jan 30, 2023
The sys_get_thread_area function in process.c in Linux 2.6 before 2.6.12.4 and 2.6.13 does not clear a data structure before copying it to userspace, which might allow a user process to obtain sensitive information.
References