The cdrom_ioctl_media_changed function in drivers/cdrom/cdrom.c in the Linux kernel before 4.16.6 allows local attackers to use a incorrect bounds check in the CDROM driver CDROM_MEDIA_CHANGED ioctl to read out kernel memory.
| Software | From | Fixed in |
|---|---|---|
| linux / linux_kernel | - | 4.16.6 |
| debian / debian_linux | 7.0 | 7.0.x |