CVE-2015-8950
published 2016-10-10CVE-2015-8950: arch/arm64/mm/dma-mapping.c in the Linux kernel before 4.0.3, as used in the ION subsystem in Android and other products, does not initialize certain data…
PriorityP422medium5.5CVSS 3.0
AVLACLPRNUIRSUCHINAN
EPSS
1.46%
70.9th percentile
arch/arm64/mm/dma-mapping.c in the Linux kernel before 4.0.3, as used in the ION subsystem in Android and other products, does not initialize certain data structures, which allows local users to obtain sensitive information from kernel memory by triggering a dma_mmap call.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.0.4-1 (bookworm) | linux 4.0.4-1 (bookworm) |
| android | — | — | |
| linux | linux_kernel | <= 4.0.2 | — |
| linux | linux_kernel | >= 0 < 4.0.4-1 | 4.0.4-1 |
| linux | linux_kernel | >= 0 < 4.0.4-1 | 4.0.4-1 |
| linux | linux_kernel | >= 0 < 4.0.4-1 | 4.0.4-1 |
| linux | linux_kernel | >= 0 < 4.0.4-1 | 4.0.4-1 |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2hcm-qr2j-ggcj: arch/arm64/mm/dma-mapping
ghsa_unreviewed·2022-05-17
CVE-2015-8950 [MEDIUM] CWE-200 GHSA-2hcm-qr2j-ggcj: arch/arm64/mm/dma-mapping
arch/arm64/mm/dma-mapping.c in the Linux kernel before 4.0.3, as used in the ION subsystem in Android and other products, does not initialize certain data structures, which allows local users to obtain sensitive information from kernel memory by triggering a dma_mmap call.
OSV
CVE-2015-8950: arch/arm64/mm/dma-mapping
osv·2016-10-10·CVSS 5.5
CVE-2015-8950 [MEDIUM] CVE-2015-8950: arch/arm64/mm/dma-mapping
arch/arm64/mm/dma-mapping.c in the Linux kernel before 4.0.3, as used in the ION subsystem in Android and other products, does not initialize certain data structures, which allows local users to obtain sensitive information from kernel memory by triggering a dma_mmap call.
Android
CVE-2015-8950: Android Security Bulletin 2016-10-01
CVE: CVE-2015-8950
Severity: HIGH
References: A-29795245
QC-CR#1041735
vendor_android·2016-10-01·CVSS 5.5
CVE-2015-8950 [MEDIUM] CVE-2015-8950: Android Security Bulletin 2016-10-01
CVE: CVE-2015-8950
Severity: HIGH
References: A-29795245
QC-CR#1041735
Android Security Bulletin 2016-10-01
CVE: CVE-2015-8950
Severity: HIGH
References: A-29795245
QC-CR#1041735
Red Hat
kernel: Missing cleaning of allocated buffers
vendor_redhat·2016-01-28·CVSS 5.5
CVE-2015-8950 [MEDIUM] CWE-456 kernel: Missing cleaning of allocated buffers
kernel: Missing cleaning of allocated buffers
arch/arm64/mm/dma-mapping.c in the Linux kernel before 4.0.3, as used in the ION subsystem in Android and other products, does not initialize certain data structures, which allows local users to obtain sensitive information from kernel memory by triggering a dma_mmap call.
A flaw was found in the Linux kernel which does not initialize certain data structures used by DMA transfer on ARM64 based systems. This could allow local users to obtain sensitive information from kernel memory by triggering a dma_mmap call and reconstructing the data.
Statement: This issue doesn't affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 5,6,7 and MRG-2. This has been rated as having Low security impact and is not currently planned to be
Debian
CVE-2015-8950: linux - arch/arm64/mm/dma-mapping.c in the Linux kernel before 4.0.3, as used in the ION...
vendor_debian·2015·CVSS 5.5
CVE-2015-8950 [MEDIUM] CVE-2015-8950: linux - arch/arm64/mm/dma-mapping.c in the Linux kernel before 4.0.3, as used in the ION...
arch/arm64/mm/dma-mapping.c in the Linux kernel before 4.0.3, as used in the ION subsystem in Android and other products, does not initialize certain data structures, which allows local users to obtain sensitive information from kernel memory by triggering a dma_mmap call.
Scope: local
bookworm: resolved (fixed in 4.0.4-1)
bullseye: resolved (fixed in 4.0.4-1)
forky: resolved (fixed in 4.0.4-1)
sid: resolved (fixed in 4.0.4-1)
trixie: resolved (fixed in 4.0.4-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-8950 kernel: Missing cleaning of allocated buffers
bugzilla·2016-10-10·CVSS 5.5
CVE-2015-8950 [MEDIUM] CVE-2015-8950 kernel: Missing cleaning of allocated buffers
CVE-2015-8950 kernel: Missing cleaning of allocated buffers
A flaw was found in the Linux kernel showed that some data structures used by DMA transfer on ARM64 based systems were not initialized.
This could allow local users to obtain sensitive information from kernel memory mapping and addresses by triggering a dma_mmap call and reconstructing the data. This is considered a kernel information leak. At this time there is no panic or denial of service that can be generated from this flaw, but this information could be used in gathering information to be used in further attacks.
Upstream patch:
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=6829e274a623187c24f7cfc0e3d35f25d087fcc5
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [
Bugzilla
CVE-2015-8950 kernel: Missing cleaning of allocated buffers [fedora-all]
bugzilla·2016-10-10·CVSS 5.5
CVE-2015-8950 [MEDIUM] CVE-2015-8950 kernel: Missing cleaning of allocated buffers [fedora-all]
CVE-2015-8950 kernel: Missing cleaning of allocated buffers [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedor
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=6829e274a623187c24f7cfc0e3d35f25d087fcc5http://source.android.com/security/bulletin/2016-10-01.htmlhttp://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.0.3http://www.securityfocus.com/bid/93318https://github.com/torvalds/linux/commit/6829e274a623187c24f7cfc0e3d35f25d087fcc5https://source.codeaurora.org/quic/la/kernel/msm-3.10/commit/?id=6e2c437a2d0a85d90d3db85a7471f99764f7bbf8http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=6829e274a623187c24f7cfc0e3d35f25d087fcc5http://source.android.com/security/bulletin/2016-10-01.htmlhttp://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.0.3http://www.securityfocus.com/bid/93318https://github.com/torvalds/linux/commit/6829e274a623187c24f7cfc0e3d35f25d087fcc5https://source.codeaurora.org/quic/la/kernel/msm-3.10/commit/?id=6e2c437a2d0a85d90d3db85a7471f99764f7bbf8
2016-10-10
Published