cve/2016/CVE-2016-4482.md
2024-05-26 14:27:05 +02:00

792 B

CVE-2016-4482

Description

The proc_connectinfo function in drivers/usb/core/devio.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via a crafted USBDEVFS_CONNECTINFO ioctl call.

POC

Reference

No PoCs from references.

Github