Impact
The issue occurs in Linux kernels on sparc64 hardware. The old itimerval structure has padding between a 64‑bit time field and a 32‑bit microsecond field. put_itimerval() fills only the named fields in a stack‑allocated __kernel_old_itimerval and copies the entire object to userspace, so getitimer() can expose the two padding holes. Zero‑initializing the aggregate before assigning the fields so implicit padding is deterministic before it crosses the user/kernel boundary mitigates the problem. This flaw is classified as CWE‑201 and only leads to information disclosure, not privilege escalation or denial of service.
Affected Systems
Linux kernels on sparc64 that do not incorporate the commit adding zero‑initialization to the __kernel_old_itimerval structure are affected. Kernel releases before that patch are vulnerable; other architectures are not impacted based on the description.
Risk and Exploitability
The CVSS score of 5.3 denotes moderate severity, while the EPSS score of less than 1% indicates a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a local user or application capable of calling getitimer, allowing unprivileged programs to read padding data but not gain higher privileges.
OpenCVE Enrichment
Debian DSA