CVE-2015-8950 PUBLISHED

arch/arm64/mm/dma-mapping.c in the Linux kernel before 4.0.3, as used in the ION subsystem in Android and other products, does not initialize certain data structures, which allows local users to obtain sensitive information from kernel memory by triggering a dma_mmap call.

EPSS 0.15% · 35.0th percentile

Risk Scores

EPSS Score
0.15%
35.0th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSlinux-lts-vivid0, 3.19.0-18.18~14.04.1, 3.19.0-20.20~14.04.1

Timeline

References

Open in Interactive Console →