cbcvebase.
CVE-2015-7884
published 2015-12-28

CVE-2015-7884: The vivid_fb_ioctl function in drivers/media/platform/vivid/vivid-osd.c in the Linux kernel through 4.3.3 does not initialize a certain structure member, which…

PriorityP46low2.3CVSS 3.0
AVLACLPRHUINSUCLINAN
EPSS
0.44%
36.3th percentile
The vivid_fb_ioctl function in drivers/media/platform/vivid/vivid-osd.c in the Linux kernel through 4.3.3 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel memory via a crafted application.

Affected

6 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 4.2.6-1 (bookworm)linux 4.2.6-1 (bookworm)
linuxlinux_kernel<= 4.3.2
linuxlinux_kernel>= 0 < 4.2.6-14.2.6-1
linuxlinux_kernel>= 0 < 4.2.6-14.2.6-1
linuxlinux_kernel>= 0 < 4.2.6-14.2.6-1
linuxlinux_kernel>= 0 < 4.2.6-14.2.6-1

CVSS provenance

nvdv3.02.3LOWCVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:P/I:N/A:N
osv4.9MEDIUM
vendor_ubuntu4.9MEDIUM
vendor_debian2.3LOW
vendor_redhat2.3LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.