Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The cfg80211_wext_giwessid function in net/wireless/wext-compat.c in the Linux kernel before 2.6.36-rc3-next-20100831 does not properly initialize certain structure members, which allows local users to leverage an off-by-one error in the ioctl_standard_iw_point function in net/wireless/wext-core.c, and obtain potentially sensitive information from kernel heap memory, via vectors involving an SIOCGIWESSID ioctl call that specifies a large buffer size.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Linux kernel 'cfg80211_wext_giwessid'函数程序设计漏洞
Vulnerability Description
Linux kernel是美国Linux基金会发布的开源操作系统Linux所使用的内核。NFSv4 implementation是其中的一个分布式文件系统协议。 Linux Kernel 2.6.36-rc3-next-20100831之前版本中的net/wireless/wext-compat.c文件中的cfg80211_wext_giwessid函数不能正确初始化某些结构体成员。本地用户可以借助涉及指定超大缓冲区大小的SIOCGIWESSID调用的向量导致net/wireless/wext-core.
CVSS Information
N/A
Vulnerability Type
N/A