An issue was discovered in the proc_pid_stack function in fs/proc/base.c in the Linux kernel through 4.18.11. It does not ensure that only root may inspect the kernel stack of an arbitrary task, allowing a local attacker to exploit racy stack unwinding and leak kernel task stack contents.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2018-10-03T22:00:00

Updated: 2024-08-05T11:01:14.755Z

Reserved: 2018-10-03T00:00:00

Link: CVE-2018-17972

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-10-03T22:29:00.800

Modified: 2023-11-07T02:54:37.033

Link: CVE-2018-17972

cve-icon Redhat

Severity : Moderate

Publid Date: 2018-09-27T00:00:00Z

Links: CVE-2018-17972 - Bugzilla