CVE-2017-14156: Infoleak
Last updated 29 November 2024
Other sources
The atyfbioctl function in drivers/video/fbdev/aty/atyfbbase.c in the Linux kernel through 4.12.10 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory by reading locations associated with padding bytes.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2017-14156.
What is the description of the vulnerability?
The atyfb_ioctl function in the Linux kernel through 4.12.10 does not initialize a certain data structure, allowing local users to obtain sensitive information from kernel stack memory.
How does the vulnerability affect the software?
The vulnerability affects the Linux kernel versions up to 4.12.10.
How can I fix the vulnerability?
To fix the vulnerability, update your Linux kernel to version 4.13.0-17.20 or later.
Where can I find more information about the vulnerability?
You can find more information about the vulnerability at the following references: [link1], [link2], [link3].