CVE-2015-8950
MEDIUMLinux Kernel < 4.0.2 - Information Disclosure
Title source: ruleDescription
arch/arm64/mm/dma-mapping.c in the Linux kernel before 4.0.3, as used in the ION subsystem in Android and other products, does not initialize certain data structures, which allows local users to obtain sensitive information from kernel memory by triggering a dma_mmap call.
References (6)
Scores
CVSS v3
5.5
EPSS
0.0015
EPSS Percentile
34.8%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Classification
CWE
CWE-200
Status
published
Affected Products (2)
linux/linux_kernel
< 4.0.2
n/a/n/a
Timeline
Published
Oct 10, 2016
Tracked Since
Feb 18, 2026