suse · CVE-2016-5244

Quick triage

Priority: medium Published: 2021-05-30 13:43:19 UTC Updated: 2025-03-22 00:58:49 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2016-5244 severity moderate: SUSE including 224 source package names (kernel-bigsmp-3.0.101-0.47.86.1, kernel-bigsmp-base-3.0.101-0.47.86.1, …), 606 product×package rows across 102 product lines (SUSE CaaS Platform 4.5, SUSE Enterprise Storage 7, … (102 product lines)): Fixed 369, Known Not Affected 237.

Description:

The rds_inc_info_copy function in net/rds/recv.c in the Linux kernel through 4.6.3 does not initialize a certain structure member, which allows remote attackers to obtain sensitive information from kernel stack memory by reading an RDS message.

cvelogic Threat Intelligence