ZeroHour

CVE-2016-8637

PoC ×2
CVSS 3.0
7.8 high
EPSS
<1%p24
Published
()
Modified
Description

A local information disclosure issue was found in dracut before 045 when generating initramfs images with world-readable permissions when 'early cpio' is used, such as when including microcode updates. Local attacker can use this to obtain sensitive information from these files, such as encryption keys or credentials.

Vendors
dracut project
Products
dracut
Weakness
CWE-732, CWE-200
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.