The ipv6_getsockopt_sticky function in net/ipv6/ipv6_sockglue.c in the Linux kernel before 2.6.20.2 allows local users to read arbitrary kernel memory via certain getsockopt calls that trigger a NULL dereference.
- http://bugzilla.kernel.org/show_bug.cgi?id=8134
No PoCs found on GitHub currently.