CVE-2015-9289
published 2019-07-27CVE-2015-9289: In the Linux kernel before 4.1.4, a buffer overflow occurs when checking userspace params in drivers/media/dvb-frontends/cx24116.c. The maximum size for a…
PriorityP426medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.42%
34.3th percentile
In the Linux kernel before 4.1.4, a buffer overflow occurs when checking userspace params in drivers/media/dvb-frontends/cx24116.c. The maximum size for a DiSEqC command is 6, according to the userspace API. However, the code allows larger values such as 23.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.1.5-1 (bookworm) | linux 4.1.5-1 (bookworm) |
| linux | linux_kernel | < 4.1.4 | 4.1.4 |
| linux | linux_kernel | >= 0 < 4.1.5-1 | 4.1.5-1 |
| linux | linux_kernel | >= 0 < 4.1.5-1 | 4.1.5-1 |
| linux | linux_kernel | >= 0 < 4.1.5-1 | 4.1.5-1 |
| linux | linux_kernel | >= 0 < 4.1.5-1 | 4.1.5-1 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:C/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: out of bound read in DVB connexant driver.
vendor_redhat·2019-07-27·CVSS 5.5
CVE-2015-9289 [MEDIUM] CWE-120 kernel: out of bound read in DVB connexant driver.
kernel: out of bound read in DVB connexant driver.
In the Linux kernel before 4.1.4, a buffer overflow occurs when checking userspace params in drivers/media/dvb-frontends/cx24116.c. The maximum size for a DiSEqC command is 6, according to the userspace API. However, the code allows larger values such as 23.
A vulnerability was found in the Linux kernel’s CX24116 tv-card driver, where an out of bounds read occurs when checking userspace params in drivers/media/dvb-frontends/cx24116.c. An attacker could use this flaw to leak kernel private information to userspace.
Statement: This flaw requires a Conexant CX24116 series TV-media card to be in the system for this driver to load. This flaw is when an attacker attempts to use the card to communicate with a satellite tv control subsystem ( v
Debian
CVE-2015-9289: linux - In the Linux kernel before 4.1.4, a buffer overflow occurs when checking userspa...
vendor_debian·2015·CVSS 5.5
CVE-2015-9289 [MEDIUM] CVE-2015-9289: linux - In the Linux kernel before 4.1.4, a buffer overflow occurs when checking userspa...
In the Linux kernel before 4.1.4, a buffer overflow occurs when checking userspace params in drivers/media/dvb-frontends/cx24116.c. The maximum size for a DiSEqC command is 6, according to the userspace API. However, the code allows larger values such as 23.
Scope: local
bookworm: resolved (fixed in 4.1.5-1)
bullseye: resolved (fixed in 4.1.5-1)
forky: resolved (fixed in 4.1.5-1)
sid: resolved (fixed in 4.1.5-1)
trixie: resolved (fixed in 4.1.5-1)
GHSA
GHSA-65g9-7jfx-8gx9: In the Linux kernel before 4
ghsa_unreviewed·2022-05-24
CVE-2015-9289 [MEDIUM] GHSA-65g9-7jfx-8gx9: In the Linux kernel before 4
In the Linux kernel before 4.1.4, a buffer overflow occurs when checking userspace params in drivers/media/dvb-frontends/cx24116.c. The maximum size for a DiSEqC command is 6, according to the userspace API. However, the code allows larger values such as 23.
OSV
CVE-2015-9289: In the Linux kernel before 4
osv·2019-07-27·CVSS 5.5
CVE-2015-9289 [MEDIUM] CVE-2015-9289: In the Linux kernel before 4
In the Linux kernel before 4.1.4, a buffer overflow occurs when checking userspace params in drivers/media/dvb-frontends/cx24116.c. The maximum size for a DiSEqC command is 6, according to the userspace API. However, the code allows larger values such as 23.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-9289 kernel: out of bound read in DVB connexant driver.
bugzilla·2019-08-01·CVSS 5.5
CVE-2015-9289 [MEDIUM] CVE-2015-9289 kernel: out of bound read in DVB connexant driver.
CVE-2015-9289 kernel: out of bound read in DVB connexant driver.
A vulnerability was found in Linux Kernel, an out-of-bounds read occurs when checking userspace params in drivers/media/dvb-frontends/cx24116.c. The maximum size for a DiSEqC command is 6, according to the userspace API. However, the code allows larger values such as 23.
This was originally classfied as a buffer-overflow but it is not. It has been reclassified as a possible information leak.
Reference:
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=1fa2337a315a2448c5434f41e00d56b01a22283c
https://github.com/torvalds/linux/commit/1fa2337a315a2448c5434f41e00d56b01a22283c
https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.1.4
Discussion:
Created kernel tracking bugs for this issue
Bugzilla
CVE-2015-9289 kernel: buffer overflow in drivers/media/dvb-frontends/cx24116.c [fedora-all]
bugzilla·2019-08-01·CVSS 5.5
CVE-2015-9289 [MEDIUM] CVE-2015-9289 kernel: buffer overflow in drivers/media/dvb-frontends/cx24116.c [fedora-all]
CVE-2015-9289 kernel: buffer overflow in drivers/media/dvb-frontends/cx24116.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supp
arXiv
Characteristics, Root Causes, and Detection of Incomplete Security Bug Fixes in the Linux Kernel
arxiv_fulltext·2025-11-21
Characteristics, Root Causes, and Detection of Incomplete Security Bug Fixes in the Linux Kernel
Characteristics, Root Causes, and Detection of
Incomplete Security Bug Fixes in the Linux Kernel
Qiang Liu^1All work was done by Aug., 2022.,
Wenlong Zhang^1,
Muhui Jiang^2,1,
Lei Wu^1,
Yajin Zhou^1
^1Zhejiang University,
^2The Hong Kong Polytechnic University
## Abstract
Security bugs in the Linux kernel emerge endlessly and have attracted much
attention.
However, fixing security bugs in the Linux kernel could be incomplete due to
human mistakes.
Specifically, an incomplete fix fails to repair all the original security
defects in the software, fails to properly repair the original security defects,
or introduces new ones.
In this paper, we study the fixes of incomplete security bugs in the Linux
kernel for the first time, and reveal their characteristics, root causes as well
as de
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=1fa2337a315a2448c5434f41e00d56b01a22283chttps://github.com/torvalds/linux/commit/1fa2337a315a2448c5434f41e00d56b01a22283chttps://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.1.4https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=1fa2337a315a2448c5434f41e00d56b01a22283chttps://github.com/torvalds/linux/commit/1fa2337a315a2448c5434f41e00d56b01a22283chttps://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.1.4
2019-07-27
Published