Vulnerability Description
arch/arm64/mm/dma-mapping.c in the Linux kernel before 4.0.3, as used in the ION subsystem in Android and other products, does not initialize certain data structures, which allows local users to obtain sensitive information from kernel memory by triggering a dma_mmap call.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | <= 4.0.2 |
Related Weaknesses (CWE)
References
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=6829e2Issue TrackingPatch
- http://source.android.com/security/bulletin/2016-10-01.htmlVendor Advisory
- http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.0.3Release Notes
- http://www.securityfocus.com/bid/93318
- https://github.com/torvalds/linux/commit/6829e274a623187c24f7cfc0e3d35f25d087fccIssue TrackingPatch
- https://source.codeaurora.org/quic/la/kernel/msm-3.10/commit/?id=6e2c437a2d0a85dIssue TrackingPatch
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=6829e2Issue TrackingPatch
- http://source.android.com/security/bulletin/2016-10-01.htmlVendor Advisory
- http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.0.3Release Notes
- http://www.securityfocus.com/bid/93318
- https://github.com/torvalds/linux/commit/6829e274a623187c24f7cfc0e3d35f25d087fccIssue TrackingPatch
- https://source.codeaurora.org/quic/la/kernel/msm-3.10/commit/?id=6e2c437a2d0a85dIssue TrackingPatch
FAQ
What is CVE-2015-8950?
CVE-2015-8950 is a vulnerability with a CVSS score of 5.5 (MEDIUM). arch/arm64/mm/dma-mapping.c in the Linux kernel before 4.0.3, as used in the ION subsystem in Android and other products, does not initialize certain data structures, which allows local users to obtai...
How severe is CVE-2015-8950?
CVE-2015-8950 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-8950?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.