An issue was discovered in the Linux kernel before 4.18.11. The ipddp_ioctl function in drivers/net/appletalk/ipddp.c allows local users to obtain sensitive kernel address information by leveraging CAP_NET_ADMIN to read the ipddp_route dev and next fields via an SIOCFINDIPDDPRT ioctl call.
4.4.0-1034.374.4.0-139.165~14.04.14.4.0-139.1654.4.0-1072.824.15.0-1047.49~16.04.14.15.0-1055.604.15.0-1040.42~16.04.14.15.0-58.64~16.04.14.4.0-1037.434.15.0-1021.23~16.04.1Exploitability
AV:LAC:LPR:LUI:NScope
S:UImpact
C:HI:NA:NCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N