Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The tc_fill_tclass function in net/sched/sch_api.c in the tc subsystem in the Linux kernel 2.4.x before 2.4.37.6 and 2.6.x before 2.6.31-rc9 does not initialize certain (1) tcm__pad1 and (2) tcm__pad2 structure members, which might allow local users to obtain sensitive information from kernel memory via unspecified vectors.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Linux Kernel 信息泄露漏洞
Vulnerability Description
Linux kernel是美国Linux基金会发布的开源操作系统Linux所使用的内核。 Linux kernel 2.4.37.6之前的2.4.x版本以及2.6.31-rc9之前的2.6.x版本的tc子系统中的net/sched/sch_api.c文件的tc_fill_tclass函数存在信息泄露漏洞,该漏洞源于程序没有初始化某些(1)tcm__pad1和(2)tcm__pad2结构成员。本地攻击者可利用该漏洞获得内核内存中的敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A