Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The copy_to_user_auth function in net/xfrm/xfrm_user.c in the Linux kernel before 3.6 uses an incorrect C library function for copying a string, which allows local users to obtain sensitive information from kernel heap memory by leveraging the CAP_NET_ADMIN capability.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Linux kernel ‘copy_to_user_auth’函数敏感信息漏洞
Vulnerability Description
Linux kernel是美国Linux基金会发布的开源操作系统Linux所使用的内核。NFSv4 implementation是其中的一个分布式文件系统协议。 Linux kernel 3.6之前版本中的net/xfrm/xfrm_user.c中的‘copy_to_user_auth’函数中存在漏洞,该漏洞源于在复制字符串期间程序使用不正确的C库函数。通过CAP_NET_ADMIN功能,本地攻击者利用该漏洞获得来自内核堆内存的敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A