ORSHIN Attack Defense Framework

Stack-Based information leak

Description

Stack-Based information leak

Risk Assesment: 6.5

CWE

909

CVE

12352

Attack Surfaces

Controller Implementation (MITRE EMB3D PID-11)

Kernel or Operating System (MITRE EMB3D PID-23)

Kernel or Operating System (MITRE EMB3D PID-23)

A2MP

Attack Vectors

Information Leak (MITRE EMB3D TID-310)

Defenses

Clear unused variable to prevent information leak, Enable CONFIG_INIT_STACK_ALL_PATTERN=y during kernel compilation