CVE-2015-9289 PUBLISHED

In the Linux kernel before 4.1.4, a buffer overflow occurs when checking userspace params in drivers/media/dvb-frontends/cx24116.c. The maximum size for a DiSEqC command is 6, according to the userspace API. However, the code allows larger values such as 23.

EPSS 0.06% · 19.5th percentile

Risk Scores

EPSS Score
0.06%
19.5th percentile

Affected Products

VendorProductVersions
Ubuntu:24.04:LTSlinux-raspi-realtime0, 6.8.0-2019.20
Ubuntu:20.04:LTSlinux-riscv0, 5.4.0-40.45, 5.4.0-39.44
Ubuntu:22.04:LTSlinux-riscv5.15.0-1012.13, 5.15.0-1011.12, 5.15.0-1008.8
Ubuntu:20.04:LTSlinux-gke5.4.0-1068.71, 0, 5.4.0-1033.35
Ubuntu:14.04:LTSlinux3.13.0-46.75, 3.13.0-46.77, 3.13.0-46.79
Ubuntu:22.04:LTSlinux-intel-iot-realtime0, 5.15.0-1073.75
Ubuntu:20.04:LTSlinux-azure-fde5.4.0-1085.90+cvm2.1, 5.4.0-1089.94+cvm1.2, 5.4.0-1090.95+cvm1.1
Ubuntu:20.04:LTSlinux-raspi20, 5.3.0-1014.16, 5.3.0-1007.8
Ubuntu:22.04:LTSlinux-realtime0, 5.15.0-1032.35

Timeline

References

Open in Interactive Console →