299,038
Total vulnerabilities in the database
The fst_get_iface function in drivers/net/wan/farsync.c in the Linux kernel before 3.11.7 does not properly initialize a certain data structure, which allows local users to obtain sensitive information from kernel memory by leveraging the CAP_NET_ADMIN capability for an SIOCWANDEV ioctl call.
| Software | From | Fixed in |
|---|---|---|
| linux / linux_kernel | 3.11.1 | 3.11.1.x |
| linux / linux_kernel | 3.11 | 3.11.x |
| linux / linux_kernel | - | 3.11.6.x |
| linux / linux_kernel | 3.11.4 | 3.11.4.x |
| linux / linux_kernel | 3.11.3 | 3.11.3.x |
| linux / linux_kernel | 3.11.2 | 3.11.2.x |
| linux / linux_kernel | 3.11.5 | 3.11.5.x |