Data Exposure Vulnerability in Linux Kernel Affecting Android Devices
CVE-2014-9900
5.5MEDIUM
What is CVE-2014-9900?
A security flaw in the ethtool_get_wol function within the Linux kernel can lead to information disclosure. Specifically, this vulnerability arises from the failure to properly initialize a data structure, allowing local users to exploit it via a crafted application. This issue affects Android devices, particularly models like the Nexus 5 and Nexus 7 (2013), prior to a patch released in August 2016.