The Orinoco driver (orinoco.c) in Linux kernel 2.6.13 and earlier does not properly clear memory from a previously used packet whose length is increased, which allows remote attackers to obtain sensitive information.
- http://www.redhat.com/support/errata/RHSA-2005-808.html
- http://www.securityfocus.com/archive/1/428028/100/0/threaded
No PoCs found on GitHub currently.