CVE-2015-7884 PUBLISHED

The vivid_fb_ioctl function in drivers/media/platform/vivid/vivid-osd.c in the Linux kernel through 4.3.3 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel memory via a crafted application.

EPSS 0.04% · 11.0th percentile

Risk Scores

EPSS Score
0.04%
11.0th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSlinux-lts-wily0, 4.2.0-18.22~14.04.1, 4.2.0-19.23~14.04.1
Ubuntu:14.04:LTSlinux-lts-vivid3.19.0-21.21~14.04.1, 3.19.0-22.22~14.04.1, 3.19.0-23.24~14.04.1

Timeline

References

Open in Interactive Console →