CVE-2014-1446

The yam_ioctl function in drivers/net/hamradio/yam.c in the Linux kernel before 3.12.8 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel memory by leveraging the CAP_NET_ADMIN capability for an SIOCYAMGCFG ioctl call.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:3.12:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:3.12.1:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:3.12.2:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:3.12.3:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:3.12.4:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:3.12.5:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:3.12.6:*:*:*:*:*:*:*

History

No history.

Information

Published : 2014-01-18 22:55

Updated : 2023-11-07 02:18


NVD link : CVE-2014-1446

Mitre link : CVE-2014-1446

CVE.ORG link : CVE-2014-1446


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-399

Resource Management Errors