Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Alan J. Wylie

#45374de 53,635
5.5CVSS total
Vulnerabilidades · 1
PT-2017-1180
5.5
2017-01-14
Linux · Linux Kernel · CVE-2017-5550
**Name of the Vulnerable Software and Affected Versions** Linux kernel versions prior to 4.9.5 **Description** The issue is related to an error in the `pipe advance` function in the Linux kernel, which can allow local users to obtain sensitive information from uninitialized heap-memory locations in certain circumstances. This can occur when reading from a pipe after an incorrect buffer-release decision. The estimated number of potentially affected devices worldwide is not specified. **Recommendations** For Linux kernel versions prior to 4.9.5, update to version 4.9.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the `pipe advance` function in the Linux kernel until a patch is available.