CyberRota Analysis
AI-GeneratedThe vulnerability in the Linux kernel affects the psample subsystem, where an information leak occurs due to improper handling of padding in netlink attributes. This can potentially expose sensitive data from memory, posing a risk to systems that rely on psample for packet sampling. Organizations using affected Linux distributions should prioritize patching to mitigate the risk of data exposure.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: net: psample: fix info leak in PSAMPLE_ATTR_DATA psample open codes nla_put() presumably to avoid wiping the data with 0s just to override it with packet data. This open coding is missing clearing the pad, however, each netlink attr is padded to 4B and data_len may not be divisible by 4B.