|Description||Integer overflow in rose_sendmsg (sys/net/af_rose.c) in the Linux kernel 18.104.22.168, and other versions before 2.6.30-rc1, might allow remote attackers to obtain sensitive information via a large length value, which causes "garbage" memory to be sent.|
|Source||CVE (at NVD; LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)|
|References||DSA-1787-1, DSA-1794-1, DSA-1800-1|
|NVD severity||medium (attack range: remote)|
The information below is based on the following data on fixed versions.