The sco_sock_getsockopt_old function in net/bluetooth/sco.c in the Linux kernel before 2.6.39 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory via the SCO_CONNINFO option.
Product | Vendor | Version |
---|---|---|
n/a | n/a | < d3f927ef0607b3c8c3f79ab6d9a4ebead3e35f4c |