CVE-2010-3078

Publication date

2010-09-21 17:00:00

Family

redhat

State

PUBLISHED

Description

The xfs_ioc_fsgetxattr function in fs/xfs/linux-2.6/xfs_ioctl.c in the Linux kernel before 2.6.36-rc4 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via an ioctl call.