CVE-2014-9900: Infoleak
Published Aug 6, 2016
·Updated
Last updated 29 November 2024
Other sources
The ethtoolgetwol function in net/core/ethtool.c in the Linux kernel through 4.7, as used in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices, does not initialize a certain data structure, which allows local users to obtain sensitive information via a crafted application, aka Android internal bug 28803952 and Qualcomm internal bug CR570754.
— Launchpad
Affected Software
3 affected components
Google Android<=6.0.1
Linux Linux Kernel<=4.7
debian/linux<=5.10.223-1, <=5.10.234-1, <=6.1.129-1, <=6.1.135-1, <=6.12.25-1, <=6.12.27-1
Remediation
Event History
Aug 6, 2016
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Jan 11, 2024
Data Sourced
via Launchpad·10:05 PM
Description
Dec 1, 2024
Data Sourced
via Ubuntu·01:23 AM
RemedyDescriptionSeverityAffected Software
Feb 23, 2025
Data Sourced
via Debian·02:21 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2014-9900.
2
What is the severity level of CVE-2014-9900?
The severity level of CVE-2014-9900 is not specified.
3
Which Linux kernel versions are affected by CVE-2014-9900?
Linux kernel versions through 4.7 are affected by CVE-2014-9900.
4
How can a local user exploit CVE-2014-9900?
A local user can exploit CVE-2014-9900 by using a crafted application to obtain sensitive information.
5
Is there a fix available for CVE-2014-9900?
Yes, there are remedies available for different Linux kernel versions affected by CVE-2014-9900.