CVE-2016-7915
published 2016-11-16CVE-2016-7915: The hid_input_field function in drivers/hid/hid-core.c in the Linux kernel before 4.6 allows physically proximate attackers to obtain sensitive information…
PriorityP424medium5.5CVSS 3.0
AVLACLPRNUIRSUCHINAN
EPSS
1.74%
75.5th percentile
The hid_input_field function in drivers/hid/hid-core.c in the Linux kernel before 4.6 allows physically proximate attackers to obtain sensitive information from kernel memory or cause a denial of service (out-of-bounds read) by connecting a device, as demonstrated by a Logitech DJ receiver.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.6.1-1 (bookworm) | linux 4.6.1-1 (bookworm) |
| android | — | — | |
| linux | linux_kernel | <= 4.5.7 | — |
| linux | linux_kernel | >= 0 < 4.6.1-1 | 4.6.1-1 |
| linux | linux_kernel | >= 0 < 4.6.1-1 | 4.6.1-1 |
| linux | linux_kernel | >= 0 < 4.6.1-1 | 4.6.1-1 |
| linux | linux_kernel | >= 0 < 4.6.1-1 | 4.6.1-1 |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2016-7915: Android Security Bulletin 2016-11-01
CVE: CVE-2016-7915
Severity: HIGH
References: A-30951261
Upstream
kernel
vendor_android·2016-11-01·CVSS 5.5
CVE-2016-7915 [MEDIUM] CVE-2016-7915: Android Security Bulletin 2016-11-01
CVE: CVE-2016-7915
Severity: HIGH
References: A-30951261
Upstream
kernel
Android Security Bulletin 2016-11-01
CVE: CVE-2016-7915
Severity: HIGH
References: A-30951261
Upstream
kernel
Red Hat
kernel: HID: core: prevent out-of-bound readings
vendor_redhat·2016-01-19·CVSS 5.5
CVE-2016-7915 [MEDIUM] CWE-125 kernel: HID: core: prevent out-of-bound readings
kernel: HID: core: prevent out-of-bound readings
The hid_input_field function in drivers/hid/hid-core.c in the Linux kernel before 4.6 allows physically proximate attackers to obtain sensitive information from kernel memory or cause a denial of service (out-of-bounds read) by connecting a device, as demonstrated by a Logitech DJ receiver.
The hid_input_field() function in 'drivers/hid/hid-core.c' in the Linux kernel before 4.6 allows physically proximate attackers to obtain sensitive information from kernel memory or cause a denial of service (out-of-bounds read) by connecting a device.
Statement: This issue affects the Linux kernel packages as shipped with Red Hat Enterprise Linux 5, 6. This has been rated as having Low security impact and is not currently planned to be addressed in fu
Debian
CVE-2016-7915: linux - The hid_input_field function in drivers/hid/hid-core.c in the Linux kernel befor...
vendor_debian·2016·CVSS 5.5
CVE-2016-7915 [MEDIUM] CVE-2016-7915: linux - The hid_input_field function in drivers/hid/hid-core.c in the Linux kernel befor...
The hid_input_field function in drivers/hid/hid-core.c in the Linux kernel before 4.6 allows physically proximate attackers to obtain sensitive information from kernel memory or cause a denial of service (out-of-bounds read) by connecting a device, as demonstrated by a Logitech DJ receiver.
Scope: local
bookworm: resolved (fixed in 4.6.1-1)
bullseye: resolved (fixed in 4.6.1-1)
forky: resolved (fixed in 4.6.1-1)
sid: resolved (fixed in 4.6.1-1)
trixie: resolved (fixed in 4.6.1-1)
GHSA
GHSA-89vx-2gvp-fw5w: The hid_input_field function in drivers/hid/hid-core
ghsa_unreviewed·2022-05-14
CVE-2016-7915 [MEDIUM] CWE-125 GHSA-89vx-2gvp-fw5w: The hid_input_field function in drivers/hid/hid-core
The hid_input_field function in drivers/hid/hid-core.c in the Linux kernel before 4.6 allows physically proximate attackers to obtain sensitive information from kernel memory or cause a denial of service (out-of-bounds read) by connecting a device, as demonstrated by a Logitech DJ receiver.
OSV
CVE-2016-7915: The hid_input_field function in drivers/hid/hid-core
osv·2016-11-16·CVSS 5.5
CVE-2016-7915 [MEDIUM] CVE-2016-7915: The hid_input_field function in drivers/hid/hid-core
The hid_input_field function in drivers/hid/hid-core.c in the Linux kernel before 4.6 allows physically proximate attackers to obtain sensitive information from kernel memory or cause a denial of service (out-of-bounds read) by connecting a device, as demonstrated by a Logitech DJ receiver.
No detection rules found.
No public exploits indexed.
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=50220dead1650609206efe91f0cc116132d59b3fhttp://rhn.redhat.com/errata/RHSA-2016-2574.htmlhttp://source.android.com/security/bulletin/2016-11-01.htmlhttp://www.securityfocus.com/bid/94138https://github.com/torvalds/linux/commit/50220dead1650609206efe91f0cc116132d59b3fhttp://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=50220dead1650609206efe91f0cc116132d59b3fhttp://rhn.redhat.com/errata/RHSA-2016-2574.htmlhttp://source.android.com/security/bulletin/2016-11-01.htmlhttp://www.securityfocus.com/bid/94138https://github.com/torvalds/linux/commit/50220dead1650609206efe91f0cc116132d59b3f
2016-11-16
Published