CVE-2014-9900 PUBLISHED

The ethtool_get_wol function in net/core/ethtool.c in the Linux kernel through 4.7, as used in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices, does not initialize a certain data structure, which allows local users to obtain sensitive information via a crafted application, aka Android internal bug 28803952 and Qualcomm internal bug CR570754.

EPSS 0.08% · 23.2th percentile

Risk Scores

EPSS Score
0.08%
23.2th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTSlinux-riscv5.4.0-40.45, 0, 5.4.0-24.28
Ubuntu:22.04:LTSlinux-realtime0, 5.15.0-1032.35
Ubuntu:20.04:LTSlinux-azure-fde5.4.0-1080.83+cvm1.1, 5.4.0-1083.87+cvm1.1, 5.4.0-1085.90+cvm1.1
Ubuntu:14.04:LTSlinux-lts-xenial0, 4.4.0-83.106~14.04.1, 4.4.0-81.104~14.04.1
Ubuntu:20.04:LTSlinux-gke0, 5.4.0-1105.112, 5.4.0-1104.111
Ubuntu:14.04:LTSlinux3.12.0-4.12, 3.13.0-53.88, 3.13.0-52.86
Ubuntu:18.04:LTSlinux-azure4.15.0-1009.9, 4.15.0-1012.12, 4.15.0-1013.13
Ubuntu:16.04:LTSlinux-hwe4.8.0-42.45~16.04.1, 0, 4.8.0-36.36~16.04.1
Ubuntu:22.04:LTSlinux-intel-iot-realtime0, 5.15.0-1073.75
Ubuntu:16.04:LTSlinux-snapdragon4.4.0-1055.59, 4.4.0-1054.58, 4.4.0-1053.57
Ubuntu:16.04:LTSlinux-raspi24.4.0-1016.22, 4.4.0-1061.69, 4.4.0-1059.67
Ubuntu:22.04:LTSlinux-riscv5.15.0-1012.13, 5.15.0-1011.12, 5.15.0-1008.8
Ubuntu:24.04:LTSlinux-raspi-realtime0, 6.8.0-2019.20
Ubuntu:16.04:LTSlinux4.4.0-7.22, 4.4.0-83.106, 4.4.0-81.104
Ubuntu:16.04:LTSlinux-aws4.4.0-1020.29, 4.4.0-1018.27, 4.4.0-1017.26
Ubuntu:18.04:LTSlinux-hwe5.3.0-28.30~18.04.1, 5.3.0-26.28~18.04.1, 5.0.0-37.40~18.04.1
Ubuntu:18.04:LTSlinux-oem4.15.0-1099.109, 4.15.0-1006.9, 4.15.0-1008.11
Ubuntu:20.04:LTSlinux-raspi25.3.0-1017.19, 5.3.0-1015.17, 5.3.0-1014.16
Ubuntu:18.04:LTSlinux-hwe-edge5.3.0-23.25~18.04.1, 5.3.0-23.25~18.04.2, 5.3.0-24.26~18.04.2
Ubuntu:16.04:LTSlinux-gke4.4.0-1008.8, 4.4.0-1010.10, 4.4.0-1012.12

…and 1 more

Timeline

References

Open in Interactive Console →