CVE-2014-4027 PUBLISHED

The rd_build_device_space function in drivers/target/target_core_rd.c in the Linux kernel before 3.14 does not properly initialize a certain data structure, which allows local users to obtain sensitive information from ramdisk_mcp memory by leveraging access to a SCSI initiator.

EPSS 0.09% · 25.7th percentile

Risk Scores

EPSS Score
0.09%
25.7th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSlinux0, 3.11.0-12.19, 3.12.0-1.3

Timeline

References

Open in Interactive Console →