← Back to CVE List

CVE-2017-14991

Published: 2017-10-04T01:29Z
Last Modified: 2024-11-21T03:13Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The sg_ioctl function in drivers/scsi/sg.c in the Linux kernel before 4.13.4 allows local users to obtain sensitive information from uninitialized kernel heap-memory locations via an SG_GET_REQUEST_TABLE ioctl call for /dev/sg0. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt