The llc_cmsg_rcv function in net/llc/af_llc.c in the Linux kernel before 4.5.5 does not initialize a certain data structure, which allows attackers to obtain sensitive information from kernel stack memory by reading a message.
| Software | From | Fixed in |
|---|---|---|
| novell / suse_linux_enterprise_server | 11-sp4 | 11-sp4.x |
| novell / suse_linux_enterprise_debuginfo | 11-sp4 | 11-sp4.x |
| novell / suse_linux_enterprise_server | 11-extra | 11-extra.x |
| novell / suse_linux_enterprise_software_development_kit | 11.0-sp4 | 11.0-sp4.x |
| canonical / ubuntu_linux | 12.04 | 12.04.x |
| canonical / ubuntu_linux | 16.04 | 16.04.x |
| canonical / ubuntu_linux | 15.10 | 15.10.x |
| canonical / ubuntu_linux | 14.04 | 14.04.x |
| linux / linux_kernel | - | 4.5.4.x |