The sys_get_thread_area function in process.c in Linux 2.6 before 2.6.12.4 and 2.6.13 does not clear a data structure before copying it to userspace, which might allow a user process to obtain sensitive information.
| Product | Vendor | Version |
|---|---|---|
| n/a | n/a | <= 6.1.* |
| n/a | n/a | < 2023.1.6 |