The ATM implementation in the Linux kernel before 3.6 does not initialize certain structures, which allows local users to obtain sensitive information from kernel stack memory via a crafted application.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Linux_kernel | Linux | * | 3.5.7 (including) |
Linux_kernel | Linux | 3.0-rc1 (including) | 3.0-rc1 (including) |
Linux_kernel | Linux | 3.0-rc2 (including) | 3.0-rc2 (including) |
Linux_kernel | Linux | 3.0-rc3 (including) | 3.0-rc3 (including) |
Linux_kernel | Linux | 3.0-rc4 (including) | 3.0-rc4 (including) |
Linux_kernel | Linux | 3.0-rc5 (including) | 3.0-rc5 (including) |
Linux_kernel | Linux | 3.0-rc6 (including) | 3.0-rc6 (including) |
Linux_kernel | Linux | 3.0-rc7 (including) | 3.0-rc7 (including) |
Linux_kernel | Linux | 3.0.1 (including) | 3.0.1 (including) |
Linux_kernel | Linux | 3.0.2 (including) | 3.0.2 (including) |
Linux_kernel | Linux | 3.0.3 (including) | 3.0.3 (including) |
Linux_kernel | Linux | 3.0.4 (including) | 3.0.4 (including) |
Linux_kernel | Linux | 3.0.5 (including) | 3.0.5 (including) |
Linux_kernel | Linux | 3.0.6 (including) | 3.0.6 (including) |
Linux_kernel | Linux | 3.0.7 (including) | 3.0.7 (including) |
Linux_kernel | Linux | 3.0.8 (including) | 3.0.8 (including) |
Linux_kernel | Linux | 3.0.9 (including) | 3.0.9 (including) |
Linux_kernel | Linux | 3.0.10 (including) | 3.0.10 (including) |
Linux_kernel | Linux | 3.0.11 (including) | 3.0.11 (including) |
Linux_kernel | Linux | 3.0.12 (including) | 3.0.12 (including) |
Linux_kernel | Linux | 3.0.13 (including) | 3.0.13 (including) |
Linux_kernel | Linux | 3.0.14 (including) | 3.0.14 (including) |
Linux_kernel | Linux | 3.0.15 (including) | 3.0.15 (including) |
Linux_kernel | Linux | 3.0.16 (including) | 3.0.16 (including) |
Linux_kernel | Linux | 3.0.17 (including) | 3.0.17 (including) |
Linux_kernel | Linux | 3.0.18 (including) | 3.0.18 (including) |
Linux_kernel | Linux | 3.0.19 (including) | 3.0.19 (including) |
Linux_kernel | Linux | 3.0.20 (including) | 3.0.20 (including) |
Linux_kernel | Linux | 3.0.21 (including) | 3.0.21 (including) |
Linux_kernel | Linux | 3.0.22 (including) | 3.0.22 (including) |
Linux_kernel | Linux | 3.0.23 (including) | 3.0.23 (including) |
Linux_kernel | Linux | 3.0.24 (including) | 3.0.24 (including) |
Linux_kernel | Linux | 3.0.25 (including) | 3.0.25 (including) |
Linux_kernel | Linux | 3.0.26 (including) | 3.0.26 (including) |
Linux_kernel | Linux | 3.0.27 (including) | 3.0.27 (including) |
Linux_kernel | Linux | 3.0.28 (including) | 3.0.28 (including) |
Linux_kernel | Linux | 3.0.29 (including) | 3.0.29 (including) |
Linux_kernel | Linux | 3.0.30 (including) | 3.0.30 (including) |
Linux_kernel | Linux | 3.0.31 (including) | 3.0.31 (including) |
Linux_kernel | Linux | 3.0.32 (including) | 3.0.32 (including) |
Linux_kernel | Linux | 3.0.33 (including) | 3.0.33 (including) |
Linux_kernel | Linux | 3.0.34 (including) | 3.0.34 (including) |
Linux_kernel | Linux | 3.0.35 (including) | 3.0.35 (including) |
Linux_kernel | Linux | 3.0.36 (including) | 3.0.36 (including) |
Linux_kernel | Linux | 3.0.37 (including) | 3.0.37 (including) |
Linux_kernel | Linux | 3.0.38 (including) | 3.0.38 (including) |
Linux_kernel | Linux | 3.0.39 (including) | 3.0.39 (including) |
Linux_kernel | Linux | 3.0.40 (including) | 3.0.40 (including) |
Linux_kernel | Linux | 3.0.41 (including) | 3.0.41 (including) |
Linux_kernel | Linux | 3.0.42 (including) | 3.0.42 (including) |
Linux_kernel | Linux | 3.0.43 (including) | 3.0.43 (including) |
Linux_kernel | Linux | 3.0.44 (including) | 3.0.44 (including) |
Linux_kernel | Linux | 3.0.45 (including) | 3.0.45 (including) |
Linux_kernel | Linux | 3.0.46 (including) | 3.0.46 (including) |
Linux_kernel | Linux | 3.0.47 (including) | 3.0.47 (including) |
Linux_kernel | Linux | 3.0.48 (including) | 3.0.48 (including) |
Linux_kernel | Linux | 3.0.49 (including) | 3.0.49 (including) |
Linux_kernel | Linux | 3.0.50 (including) | 3.0.50 (including) |
Linux_kernel | Linux | 3.0.51 (including) | 3.0.51 (including) |
Linux_kernel | Linux | 3.0.52 (including) | 3.0.52 (including) |
Linux_kernel | Linux | 3.0.53 (including) | 3.0.53 (including) |
Linux_kernel | Linux | 3.0.54 (including) | 3.0.54 (including) |
Linux_kernel | Linux | 3.0.55 (including) | 3.0.55 (including) |
Linux_kernel | Linux | 3.0.56 (including) | 3.0.56 (including) |
Linux_kernel | Linux | 3.0.57 (including) | 3.0.57 (including) |
Linux_kernel | Linux | 3.0.58 (including) | 3.0.58 (including) |
Linux_kernel | Linux | 3.0.59 (including) | 3.0.59 (including) |
Linux_kernel | Linux | 3.0.60 (including) | 3.0.60 (including) |
Linux_kernel | Linux | 3.0.61 (including) | 3.0.61 (including) |
Linux_kernel | Linux | 3.0.62 (including) | 3.0.62 (including) |
Linux_kernel | Linux | 3.0.63 (including) | 3.0.63 (including) |
Linux_kernel | Linux | 3.0.64 (including) | 3.0.64 (including) |
Linux_kernel | Linux | 3.0.65 (including) | 3.0.65 (including) |
Linux_kernel | Linux | 3.0.66 (including) | 3.0.66 (including) |
Linux_kernel | Linux | 3.0.67 (including) | 3.0.67 (including) |
Linux_kernel | Linux | 3.0.68 (including) | 3.0.68 (including) |
Linux_kernel | Linux | 3.1 (including) | 3.1 (including) |
Linux_kernel | Linux | 3.1-rc1 (including) | 3.1-rc1 (including) |
Linux_kernel | Linux | 3.1-rc2 (including) | 3.1-rc2 (including) |
Linux_kernel | Linux | 3.1-rc3 (including) | 3.1-rc3 (including) |
Linux_kernel | Linux | 3.1-rc4 (including) | 3.1-rc4 (including) |
Linux_kernel | Linux | 3.1.1 (including) | 3.1.1 (including) |
Linux_kernel | Linux | 3.1.2 (including) | 3.1.2 (including) |
Linux_kernel | Linux | 3.1.3 (including) | 3.1.3 (including) |
Linux_kernel | Linux | 3.1.4 (including) | 3.1.4 (including) |
Linux_kernel | Linux | 3.1.5 (including) | 3.1.5 (including) |
Linux_kernel | Linux | 3.1.6 (including) | 3.1.6 (including) |
Linux_kernel | Linux | 3.1.7 (including) | 3.1.7 (including) |
Linux_kernel | Linux | 3.1.8 (including) | 3.1.8 (including) |
Linux_kernel | Linux | 3.1.9 (including) | 3.1.9 (including) |
Linux_kernel | Linux | 3.1.10 (including) | 3.1.10 (including) |
Linux_kernel | Linux | 3.2 (including) | 3.2 (including) |
Linux_kernel | Linux | 3.2-rc2 (including) | 3.2-rc2 (including) |
Linux_kernel | Linux | 3.2-rc3 (including) | 3.2-rc3 (including) |
Linux_kernel | Linux | 3.2-rc4 (including) | 3.2-rc4 (including) |
Linux_kernel | Linux | 3.2-rc5 (including) | 3.2-rc5 (including) |
Linux_kernel | Linux | 3.2-rc6 (including) | 3.2-rc6 (including) |
Linux_kernel | Linux | 3.2-rc7 (including) | 3.2-rc7 (including) |
Linux_kernel | Linux | 3.2.1 (including) | 3.2.1 (including) |
Linux_kernel | Linux | 3.2.2 (including) | 3.2.2 (including) |
Linux_kernel | Linux | 3.2.3 (including) | 3.2.3 (including) |
Linux_kernel | Linux | 3.2.4 (including) | 3.2.4 (including) |
Linux_kernel | Linux | 3.2.5 (including) | 3.2.5 (including) |
Linux_kernel | Linux | 3.2.6 (including) | 3.2.6 (including) |
Linux_kernel | Linux | 3.2.7 (including) | 3.2.7 (including) |
Linux_kernel | Linux | 3.2.8 (including) | 3.2.8 (including) |
Linux_kernel | Linux | 3.2.9 (including) | 3.2.9 (including) |
Linux_kernel | Linux | 3.2.10 (including) | 3.2.10 (including) |
Linux_kernel | Linux | 3.2.11 (including) | 3.2.11 (including) |
Linux_kernel | Linux | 3.2.12 (including) | 3.2.12 (including) |
Linux_kernel | Linux | 3.2.13 (including) | 3.2.13 (including) |
Linux_kernel | Linux | 3.2.14 (including) | 3.2.14 (including) |
Linux_kernel | Linux | 3.2.15 (including) | 3.2.15 (including) |
Linux_kernel | Linux | 3.2.16 (including) | 3.2.16 (including) |
Linux_kernel | Linux | 3.2.17 (including) | 3.2.17 (including) |
Linux_kernel | Linux | 3.2.18 (including) | 3.2.18 (including) |
Linux_kernel | Linux | 3.2.19 (including) | 3.2.19 (including) |
Linux_kernel | Linux | 3.2.20 (including) | 3.2.20 (including) |
Linux_kernel | Linux | 3.2.21 (including) | 3.2.21 (including) |
Linux_kernel | Linux | 3.2.22 (including) | 3.2.22 (including) |
Linux_kernel | Linux | 3.2.23 (including) | 3.2.23 (including) |
Linux_kernel | Linux | 3.2.24 (including) | 3.2.24 (including) |
Linux_kernel | Linux | 3.2.25 (including) | 3.2.25 (including) |
Linux_kernel | Linux | 3.2.26 (including) | 3.2.26 (including) |
Linux_kernel | Linux | 3.2.27 (including) | 3.2.27 (including) |
Linux_kernel | Linux | 3.2.28 (including) | 3.2.28 (including) |
Linux_kernel | Linux | 3.2.29 (including) | 3.2.29 (including) |
Linux_kernel | Linux | 3.2.30 (including) | 3.2.30 (including) |
Linux_kernel | Linux | 3.3 (including) | 3.3 (including) |
Linux_kernel | Linux | 3.3-rc1 (including) | 3.3-rc1 (including) |
Linux_kernel | Linux | 3.3-rc2 (including) | 3.3-rc2 (including) |
Linux_kernel | Linux | 3.3-rc3 (including) | 3.3-rc3 (including) |
Linux_kernel | Linux | 3.3-rc4 (including) | 3.3-rc4 (including) |
Linux_kernel | Linux | 3.3-rc5 (including) | 3.3-rc5 (including) |
Linux_kernel | Linux | 3.3-rc6 (including) | 3.3-rc6 (including) |
Linux_kernel | Linux | 3.3-rc7 (including) | 3.3-rc7 (including) |
Linux_kernel | Linux | 3.3.1 (including) | 3.3.1 (including) |
Linux_kernel | Linux | 3.3.2 (including) | 3.3.2 (including) |
Linux_kernel | Linux | 3.3.3 (including) | 3.3.3 (including) |
Linux_kernel | Linux | 3.3.4 (including) | 3.3.4 (including) |
Linux_kernel | Linux | 3.3.5 (including) | 3.3.5 (including) |
Linux_kernel | Linux | 3.3.6 (including) | 3.3.6 (including) |
Linux_kernel | Linux | 3.3.7 (including) | 3.3.7 (including) |
Linux_kernel | Linux | 3.3.8 (including) | 3.3.8 (including) |
Linux_kernel | Linux | 3.4 (including) | 3.4 (including) |
Linux_kernel | Linux | 3.4-rc1 (including) | 3.4-rc1 (including) |
Linux_kernel | Linux | 3.4-rc2 (including) | 3.4-rc2 (including) |
Linux_kernel | Linux | 3.4-rc3 (including) | 3.4-rc3 (including) |
Linux_kernel | Linux | 3.4-rc4 (including) | 3.4-rc4 (including) |
Linux_kernel | Linux | 3.4-rc5 (including) | 3.4-rc5 (including) |
Linux_kernel | Linux | 3.4-rc6 (including) | 3.4-rc6 (including) |
Linux_kernel | Linux | 3.4-rc7 (including) | 3.4-rc7 (including) |
Linux_kernel | Linux | 3.4.1 (including) | 3.4.1 (including) |
Linux_kernel | Linux | 3.4.2 (including) | 3.4.2 (including) |
Linux_kernel | Linux | 3.4.3 (including) | 3.4.3 (including) |
Linux_kernel | Linux | 3.4.4 (including) | 3.4.4 (including) |
Linux_kernel | Linux | 3.4.5 (including) | 3.4.5 (including) |
Linux_kernel | Linux | 3.4.6 (including) | 3.4.6 (including) |
Linux_kernel | Linux | 3.4.7 (including) | 3.4.7 (including) |
Linux_kernel | Linux | 3.4.8 (including) | 3.4.8 (including) |
Linux_kernel | Linux | 3.4.9 (including) | 3.4.9 (including) |
Linux_kernel | Linux | 3.4.10 (including) | 3.4.10 (including) |
Linux_kernel | Linux | 3.4.11 (including) | 3.4.11 (including) |
Linux_kernel | Linux | 3.4.12 (including) | 3.4.12 (including) |
Linux_kernel | Linux | 3.4.13 (including) | 3.4.13 (including) |
Linux_kernel | Linux | 3.4.14 (including) | 3.4.14 (including) |
Linux_kernel | Linux | 3.4.15 (including) | 3.4.15 (including) |
Linux_kernel | Linux | 3.4.16 (including) | 3.4.16 (including) |
Linux_kernel | Linux | 3.4.17 (including) | 3.4.17 (including) |
Linux_kernel | Linux | 3.4.18 (including) | 3.4.18 (including) |
Linux_kernel | Linux | 3.4.19 (including) | 3.4.19 (including) |
Linux_kernel | Linux | 3.4.20 (including) | 3.4.20 (including) |
Linux_kernel | Linux | 3.4.21 (including) | 3.4.21 (including) |
Linux_kernel | Linux | 3.4.22 (including) | 3.4.22 (including) |
Linux_kernel | Linux | 3.4.23 (including) | 3.4.23 (including) |
Linux_kernel | Linux | 3.4.24 (including) | 3.4.24 (including) |
Linux_kernel | Linux | 3.4.25 (including) | 3.4.25 (including) |
Linux_kernel | Linux | 3.4.26 (including) | 3.4.26 (including) |
Linux_kernel | Linux | 3.4.27 (including) | 3.4.27 (including) |
Linux_kernel | Linux | 3.4.28 (including) | 3.4.28 (including) |
Linux_kernel | Linux | 3.4.29 (including) | 3.4.29 (including) |
Linux_kernel | Linux | 3.4.30 (including) | 3.4.30 (including) |
Linux_kernel | Linux | 3.4.31 (including) | 3.4.31 (including) |
Linux_kernel | Linux | 3.4.32 (including) | 3.4.32 (including) |
Linux_kernel | Linux | 3.5.1 (including) | 3.5.1 (including) |
Linux_kernel | Linux | 3.5.2 (including) | 3.5.2 (including) |
Linux_kernel | Linux | 3.5.3 (including) | 3.5.3 (including) |
Linux_kernel | Linux | 3.5.4 (including) | 3.5.4 (including) |
Linux_kernel | Linux | 3.5.5 (including) | 3.5.5 (including) |
Linux_kernel | Linux | 3.5.6 (including) | 3.5.6 (including) |
Red Hat Enterprise Linux 5 | RedHat | kernel-0:2.6.18-348.4.1.el5 | * |
Red Hat Enterprise Linux 6 | RedHat | kernel-0:2.6.32-358.6.1.el6 | * |
Linux | Ubuntu | hardy | * |
Linux | Ubuntu | lucid | * |
Linux | Ubuntu | oneiric | * |
Linux | Ubuntu | precise | * |
Linux | Ubuntu | upstream | * |
Linux-armadaxp | Ubuntu | precise | * |
Linux-armadaxp | Ubuntu | upstream | * |
Linux-aws | Ubuntu | upstream | * |
Linux-ec2 | Ubuntu | lucid | * |
Linux-ec2 | Ubuntu | upstream | * |
Linux-flo | Ubuntu | esm-apps/xenial | * |
Linux-flo | Ubuntu | trusty | * |
Linux-flo | Ubuntu | trusty/esm | * |
Linux-flo | Ubuntu | upstream | * |
Linux-flo | Ubuntu | utopic | * |
Linux-flo | Ubuntu | vivid | * |
Linux-flo | Ubuntu | vivid/stable-phone-overlay | * |
Linux-flo | Ubuntu | wily | * |
Linux-flo | Ubuntu | xenial | * |
Linux-flo | Ubuntu | yakkety | * |
Linux-fsl-imx51 | Ubuntu | lucid | * |
Linux-fsl-imx51 | Ubuntu | upstream | * |
Linux-gke | Ubuntu | upstream | * |
Linux-goldfish | Ubuntu | saucy | * |
Linux-goldfish | Ubuntu | trusty | * |
Linux-goldfish | Ubuntu | trusty/esm | * |
Linux-goldfish | Ubuntu | upstream | * |
Linux-grouper | Ubuntu | saucy | * |
Linux-grouper | Ubuntu | trusty | * |
Linux-grouper | Ubuntu | upstream | * |
Linux-grouper | Ubuntu | utopic | * |
Linux-hwe | Ubuntu | upstream | * |
Linux-hwe-edge | Ubuntu | upstream | * |
Linux-linaro-omap | Ubuntu | oneiric | * |
Linux-linaro-omap | Ubuntu | precise | * |
Linux-linaro-omap | Ubuntu | quantal | * |
Linux-linaro-omap | Ubuntu | upstream | * |
Linux-linaro-shared | Ubuntu | oneiric | * |
Linux-linaro-shared | Ubuntu | precise | * |
Linux-linaro-shared | Ubuntu | quantal | * |
Linux-linaro-shared | Ubuntu | upstream | * |
Linux-linaro-vexpress | Ubuntu | oneiric | * |
Linux-linaro-vexpress | Ubuntu | precise | * |
Linux-linaro-vexpress | Ubuntu | quantal | * |
Linux-linaro-vexpress | Ubuntu | upstream | * |
Linux-lts-backport-maverick | Ubuntu | lucid | * |
Linux-lts-backport-maverick | Ubuntu | upstream | * |
Linux-lts-backport-oneiric | Ubuntu | lucid | * |
Linux-lts-backport-oneiric | Ubuntu | upstream | * |
Linux-lts-quantal | Ubuntu | upstream | * |
Linux-lts-raring | Ubuntu | upstream | * |
Linux-lts-trusty | Ubuntu | upstream | * |
Linux-lts-utopic | Ubuntu | upstream | * |
Linux-lts-vivid | Ubuntu | upstream | * |
Linux-lts-wily | Ubuntu | upstream | * |
Linux-lts-xenial | Ubuntu | upstream | * |
Linux-maguro | Ubuntu | saucy | * |
Linux-maguro | Ubuntu | trusty | * |
Linux-maguro | Ubuntu | upstream | * |
Linux-mako | Ubuntu | esm-apps/xenial | * |
Linux-mako | Ubuntu | saucy | * |
Linux-mako | Ubuntu | trusty | * |
Linux-mako | Ubuntu | trusty/esm | * |
Linux-mako | Ubuntu | upstream | * |
Linux-mako | Ubuntu | utopic | * |
Linux-mako | Ubuntu | vivid | * |
Linux-mako | Ubuntu | vivid/stable-phone-overlay | * |
Linux-mako | Ubuntu | wily | * |
Linux-mako | Ubuntu | xenial | * |
Linux-mako | Ubuntu | yakkety | * |
Linux-manta | Ubuntu | saucy | * |
Linux-manta | Ubuntu | upstream | * |
Linux-mvl-dove | Ubuntu | lucid | * |
Linux-mvl-dove | Ubuntu | upstream | * |
Linux-qcm-msm | Ubuntu | lucid | * |
Linux-qcm-msm | Ubuntu | oneiric | * |
Linux-qcm-msm | Ubuntu | precise | * |
Linux-qcm-msm | Ubuntu | quantal | * |
Linux-qcm-msm | Ubuntu | upstream | * |
Linux-raspi2 | Ubuntu | upstream | * |
Linux-raspi2 | Ubuntu | vivid/ubuntu-core | * |
Linux-snapdragon | Ubuntu | upstream | * |
Linux-ti-omap4 | Ubuntu | oneiric | * |
Linux-ti-omap4 | Ubuntu | precise | * |
Linux-ti-omap4 | Ubuntu | upstream | * |
There are many different kinds of mistakes that introduce information exposures. The severity of the error can range widely, depending on the context in which the product operates, the type of sensitive information that is revealed, and the benefits it may provide to an attacker. Some kinds of sensitive information include:
Information might be sensitive to different parties, each of which may have their own expectations for whether the information should be protected. These parties include:
Information exposures can occur in different ways:
It is common practice to describe any loss of confidentiality as an “information exposure,” but this can lead to overuse of CWE-200 in CWE mapping. From the CWE perspective, loss of confidentiality is a technical impact that can arise from dozens of different weaknesses, such as insecure file permissions or out-of-bounds read. CWE-200 and its lower-level descendants are intended to cover the mistakes that occur in behaviors that explicitly manage, store, transfer, or cleanse sensitive information.