Red Hat Bugzilla – Bug 1350796
CVE-2014-9903 kernel: Information leak in sys_sched_getattr()
Last modified: 2016-06-28 08:27:54 EDT
The sched_read_attr function in kernel/sched/core.c in the Linux kernel 3.14-rc before 3.14-rc4 uses an incorrect size, which allows local users to obtain sensitive information from kernel stack memory via a crafted sched_getattr system call. Upstream fix: https://github.com/torvalds/linux/commit/4efbc454ba68def5ef285b26ebfcfdb605b52755