CVE-2025-0662
CVE-2025-0662
Título es
CVE-2025-0662
Jue, 30/01/2025 – 05:15
Tipo
CWE-122
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2025-0662
Descripción en
In some cases, the ktrace facility will log the contents of kernel structures to userspace. In one such case, ktrace dumps a variable-sized sockaddr to userspace. There, the full sockaddr is copied, even when it is shorter than the full size. This can result in up to 14 uninitialized bytes of kernel memory being copied out to userspace.
It is possible for an unprivileged userspace program to leak 14 bytes of a kernel heap allocation to userspace.
30/01/2025
30/01/2025
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
Pendiente de análisis
Enviar en el boletín
Off