In the Linux kernel before 5.2.14, rds6incinfo_copy in net/rds/recv.c allows attackers to obtain sensitive information from kernel stack memory because tos and flags fields are not initialized.
[
{
"deprecated": false,
"signature_version": "v1",
"digest": {
"function_hash": "323175174116006736367617789921837833552",
"length": 547.0
},
"target": {
"function": "rds6_inc_info_copy",
"file": "net/rds/recv.c"
},
"id": "CVE-2019-16714-5aa6f8ac",
"source": "https://github.com/torvalds/linux/commit/7d0a06586b2686ba80c4a2da5f91cb10ffbea736",
"signature_type": "Function"
},
{
"deprecated": false,
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"255212118642456291440683210435881102075",
"270208186230961866274760800974596681779",
"167062064257216133080716191825438507670",
"30770943032444953230003529903219742171",
"299424386392896070712404146147839370278",
"253315866562584575356851045810074718981",
"331498920963108893021588706279381112765",
"174353265596285021529529645320588734242"
]
},
"target": {
"file": "net/rds/recv.c"
},
"id": "CVE-2019-16714-6d680486",
"source": "https://github.com/torvalds/linux/commit/7d0a06586b2686ba80c4a2da5f91cb10ffbea736",
"signature_type": "Line"
}
]