Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The bluetooth subsystem in the Linux kernel before 3.0-rc4 does not properly initialize certain data structures, which allows local users to obtain potentially sensitive information from kernel memory via a crafted getsockopt system call, related to (1) the l2cap_sock_getsockopt_old function in net/bluetooth/l2cap_sock.c and (2) the rfcomm_sock_getsockopt_old function in net/bluetooth/rfcomm/sock.c.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Linux Kernel Bluetooth 'l2cap_sock.c'和'rfcomm/sock.c'信息泄露漏洞
Vulnerability Description
Linux kernel是美国Linux基金会发布的开源操作系统Linux所使用的内核。NFSv4 implementation是其中的一个分布式文件系统协议。 Linux kernel的Bluetooth中存在信息泄露漏洞。该漏洞源于l2cap_sock.c和rfcomm/sock.c中的错误,结构“l2cap_conninfo”和“rfcomm_conninfo”每个都有一个填充字节,此字节在“cinfo”中被复制到未初始化的用户空间。远程攻击者可借助特制的getsockopt系统调用获取内核内存的敏
CVSS Information
N/A
Vulnerability Type
N/A