Data Leakage Vulnerability in Linux Kernel Affecting Android Devices
CVE-2014-9895

5.5MEDIUM

Key Information:

Vendor

Linux

Vendor
CVE Published:
6 August 2016

What is CVE-2014-9895?

A vulnerability exists in the Linux kernel affecting specific Android devices, where improper initialization of data structures can result in unauthorized access to sensitive information. This flaw enables local users to exploit the issue through specially crafted applications, potentially leading to information disclosure. The vulnerability was noted in devices such as the Nexus 5 and Nexus 7 (2013) and requires appropriate patches to mitigate the risks associated with this data leakage.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.