FUSE 2.x before 2.3.0 does not properly clear previously used memory from unfilled pages when the filesystem returns a short byte count to a read request, which may allow local users to obtain sensitive information.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Fuse | Fuse | 2.2 (including) | 2.2 (including) |
Fuse | Fuse | 2.2.1 (including) | 2.2.1 (including) |
Fuse | Fuse | 2.3_pre (including) | 2.3_pre (including) |
Fuse | Fuse | 2.3_rc1 (including) | 2.3_rc1 (including) |