CVE-2016-4580 PUBLISHED

The x25_negotiate_facilities function in net/x25/x25_facilities.c in the Linux kernel before 4.5.5 does not properly initialize a certain data structure, which allows attackers to obtain sensitive information from kernel stack memory via an X.25 Call Request.

EPSS 1.55% · 81.3th percentile

Risk Scores

EPSS Score
1.55%
81.3th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSlinux4.4.0-11.26, 4.4.0-9.24, 4.4.0-7.22
Ubuntu:16.04:LTSlinux-snapdragon4.4.0-1012.12, 4.4.0-1013.15, 4.4.0-1015.18
Ubuntu:14.04:LTSlinux-lts-xenial*, 0, 4.4.0-13.29~14.04.1
Ubuntu:14.04:LTSlinux-lts-wily0, *, 4.2.0-38.45~14.04.1
Ubuntu:16.04:LTSlinux-raspi24.4.0-1004.5, 4.4.0-1012.16, 4.4.0-1010.13
Ubuntu:14.04:LTSlinux3.13.0-51.84, 3.13.0-23.45, 3.13.0-55.92
Ubuntu:14.04:LTSlinux-lts-utopic0, 3.16.0-55.74~14.04.1, 3.16.0-53.72~14.04.1
Ubuntu:14.04:LTSlinux-lts-vivid3.19.0-59.66~14.04.1, 3.19.0-61.69~14.04.1, *

Timeline

References

Open in Interactive Console →