The llccmsgrcv function in net/llc/af_llc.c in the Linux kernel before 4.5.5 does not initialize a certain data structure, which allows attackers to obtain sensitive information from kernel stack memory by reading a message.
{ "vanir_signatures": [ { "target": { "file": "net/llc/af_llc.c", "function": "llc_cmsg_rcv" }, "source": "https://github.com/torvalds/linux/commit/b8670c09f37bdf2847cc44f36511a53afc6161fd", "deprecated": false, "signature_version": "v1", "id": "CVE-2016-4485-495c112c", "digest": { "function_hash": "89811586475523581743380218049371733811", "length": 375.0 }, "signature_type": "Function" }, { "target": { "file": "net/llc/af_llc.c" }, "source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@b8670c09f37bdf2847cc44f36511a53afc6161fd", "deprecated": false, "signature_version": "v1", "id": "CVE-2016-4485-a1b07ad7", "digest": { "threshold": 0.9, "line_hashes": [ "121970777427102411744872781396669618427", "337112444865369004091308920332469047521", "267336713482998994220398686187532757493" ] }, "signature_type": "Line" }, { "target": { "file": "net/llc/af_llc.c" }, "source": "https://github.com/torvalds/linux/commit/b8670c09f37bdf2847cc44f36511a53afc6161fd", "deprecated": false, "signature_version": "v1", "id": "CVE-2016-4485-bae64523", "digest": { "threshold": 0.9, "line_hashes": [ "121970777427102411744872781396669618427", "337112444865369004091308920332469047521", "267336713482998994220398686187532757493" ] }, "signature_type": "Line" }, { "target": { "file": "net/llc/af_llc.c", "function": "llc_cmsg_rcv" }, "source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@b8670c09f37bdf2847cc44f36511a53afc6161fd", "deprecated": false, "signature_version": "v1", "id": "CVE-2016-4485-c1969663", "digest": { "function_hash": "89811586475523581743380218049371733811", "length": 375.0 }, "signature_type": "Function" } ] }