CVE-2017-14156
Moderate
CVE-2017-14156
The atyfb_ioctl function in drivers/video/fbdev/aty/atyfb_base.c in the Linux kernel through 4.12.10 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory by reading locations associated with padding bytes.
Exploit probability
0.4%
Published
September 5, 2017
Required by
Not available
Last source change
April 16, 2026
02 / AFFECTED SOFTWARE
Affected packages
04 / EVIDENCE
Source records
Open Source Vulnerabilities
CVE-2017-14156
View original source
The atyfb_ioctl function in drivers/video/fbdev/aty/atyfb_base.c in the Linux kernel through 4.12.10 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory by reading locations associated with padding bytes.
05 / REFERENCES
Further evidence
- http://www.debian.org/security/2017/dsa-3981
- http://www.securityfocus.com/bid/100634
- https://github.com/torvalds/linux/pull/441
- https://marc.info/?l=linux-kernel&m=150401461613306&w=2
- https://marc.info/?l=linux-kernel&m=150453196710422&w=2
- https://usn.ubuntu.com/3583-1/
- https://usn.ubuntu.com/3583-2/