The ethtool_get_wol function in net/core/ethtool.c in the Linux kernel through 4.7, as used in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices, does not initialize a certain data structure, which allows local users to obtain sensitive information via a crafted application, aka Android internal bug 28803952 and Qualcomm internal bug CR570754.
Advisories
Source ID Title
EUVD EUVD EUVD-2014-9705 The ethtool_get_wol function in net/core/ethtool.c in the Linux kernel through 4.7, as used in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices, does not initialize a certain data structure, which allows local users to obtain sensitive information via a crafted application, aka Android internal bug 28803952 and Qualcomm internal bug CR570754.
Ubuntu USN Ubuntu USN USN-3358-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-3359-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-3360-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-3360-2 Linux kernel (Trusty HWE) vulnerabilities
Ubuntu USN Ubuntu USN USN-3364-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-3364-2 Linux kernel (Xenial HWE) vulnerabilities
Ubuntu USN Ubuntu USN USN-3364-3 Linux kernel (AWS, GKE) vulnerabilities
Ubuntu USN Ubuntu USN USN-3371-1 Linux kernel (HWE) kernel vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: google_android

Published:

Updated: 2024-08-06T14:02:37.856Z

Reserved: 2016-06-24T00:00:00

Link: CVE-2014-9900

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2016-08-06T10:59:44.983

Modified: 2025-04-12T10:46:40.837

Link: CVE-2014-9900

cve-icon Redhat

Severity : Moderate

Publid Date: 2017-07-25T00:00:00Z

Links: CVE-2014-9900 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses