In kernel/compat.c in the Linux kernel, as used in Google Chrome OS and other products, there is a possible out-of-bounds read. restart_syscall uses uninitialized data when restarting compat_sys_nanosleep. NOTE: this is disputed because the code path is unreachable. Reference: https://bugs.chromium.org/p/chromium/issues/detail?id=408827 https://lkml.org/lkml/2014/9/7/29
Created kernel tracking bugs for this issue: Affects: fedora-all [bug 1775122]
This was fixed upstream in 3.17, and has never been an issue in any currently supported fedora release.