The sco_sock_getsockopt_old function in net/bluetooth/sco.c in the Linux kernel before 2.6.39 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory via the SCO_CONNINFO option.
- https://bugzilla.redhat.com/show_bug.cgi?id=681259
No PoCs found on GitHub currently.