Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A vulnerability in the Linux kernel's IIO acceleration driver for the SCA3300 sensor has been addressed. This issue involved a potential leak of uninitialized stack data to userspace. The vulnerability was caused by the 'channels' array not being properly initialized before use. The problem has been fixed by ensuring the array is zeroed out prior to utilization.
Exploitation of this vulnerability could lead to the unintentional disclosure of uninitialized stack data to userspace, which may be exploited to cause undefined behavior or information leakage.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.