UBUNTU-CVE-2017-5967
The time subsystem in the Linux kernel through 4.9.9, when CONFIG_TIMER_STATS is enabled, allows local users to discover real PID values (as distinguished from PID values inside a PID namespace) by reading the /proc/timer_list file, related to the print_timer function in kernel/time/timer_list.c and the __timer_stats_timer_set_start_info function in kernel/time/timer.c.
02 / AFFECTED SOFTWARE
Affected packages
125 explicit affected versions
81 explicit affected versions
5 explicit affected versions
26 explicit affected versions
60 explicit affected versions
94 explicit affected versions
92 explicit affected versions
4 explicit affected versions
26 explicit affected versions
1 explicit affected versions
1 explicit affected versions
23 explicit affected versions
1 explicit affected versions
11 explicit affected versions
191 explicit affected versions
59 explicit affected versions
103 explicit affected versions
57 explicit affected versions
2 explicit affected versions
38 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
The time subsystem in the Linux kernel through 4.9.9, when CONFIG_TIMER_STATS is enabled, allows local users to discover real PID values (as distinguished from PID values inside a PID namespace) by reading the /proc/timer_list file, related to the print_timer function in kernel/time/timer_list.c and the __timer_stats_timer_set_start_info function in kernel/time/timer.c.
05 / REFERENCES