Information Disclosure Vulnerability in Genlock Driver for Linux Kernel 3.x

Information Disclosure Vulnerability in Genlock Driver for Linux Kernel 3.x

CVE-2013-6392 · MEDIUM Severity

AV:L/AC:L/AU:N/C:C/I:N/A:N

The genlock_dev_ioctl function in genlock.c in the Genlock driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not properly initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via a crafted GENLOCK_IOC_EXPORT ioctl call.

Learn more about our Cis Benchmark Audit For Distribution Independent Linux.