An issue was discovered in drivers/scsi/aacraid/commctrl.c in the Linux kernel. There is potential exposure of kernel stack memory because aac_get_hba_info does not initialize the hbainfo structure. Reference: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=342ffc26693b528648bdc9377e51e4f2450b4860
Created kernel tracking bugs for this issue: Affects: fedora-all [bug 1757376]
This was fixed in upstream kernel 4.13 and has never impacted any still currently supported release of Fedora.
Mitigation: There is no known mitigation to this flaw, preventing users being able to issue an ioctl to this device by removing the relevant permissions to do so will limit the information exposure.
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2017-18550