In the Linux kernel before 5.2.14, rds6incinfo_copy in net/rds/recv.c allows attackers to obtain sensitive information from kernel stack memory because tos and flags fields are not initialized.
{ "vanir_signatures": [ { "signature_type": "Function", "deprecated": false, "signature_version": "v1", "source": "https://github.com/torvalds/linux/commit/7d0a06586b2686ba80c4a2da5f91cb10ffbea736", "id": "CVE-2019-16714-5aa6f8ac", "digest": { "function_hash": "323175174116006736367617789921837833552", "length": 547.0 }, "target": { "function": "rds6_inc_info_copy", "file": "net/rds/recv.c" } }, { "signature_type": "Line", "deprecated": false, "signature_version": "v1", "source": "https://github.com/torvalds/linux/commit/7d0a06586b2686ba80c4a2da5f91cb10ffbea736", "id": "CVE-2019-16714-6d680486", "digest": { "line_hashes": [ "255212118642456291440683210435881102075", "270208186230961866274760800974596681779", "167062064257216133080716191825438507670", "30770943032444953230003529903219742171", "299424386392896070712404146147839370278", "253315866562584575356851045810074718981", "331498920963108893021588706279381112765", "174353265596285021529529645320588734242" ], "threshold": 0.9 }, "target": { "file": "net/rds/recv.c" } } ] }