CVE-2015-8575

CVSS v3.0 4 (Medium)
40% Progress
CVSS v2.0 2.1 (Low)
21% Progress
EPSS 0.11 % (45th)
0.11% Progress
Affected Products 1
Advisories 20

The sco_sock_bind function in net/bluetooth/sco.c in the Linux kernel before 4.3.4 does not verify an address length, which allows local users to obtain sensitive information from kernel memory and bypass the KASLR protection mechanism via a crafted application.

Weaknesses
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
CVE Status
PUBLISHED
CNA
OpenText
Published Date
2016-02-08 03:59:04
(8 years ago)
Updated Date
2023-11-07 02:28:33
(10 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Linux Kernel 4.3.3 and prior versions cpe:2.3:o:linux:linux_kernel <= 4.3.3
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...