CVE-2015-8950: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 1.5% chance of exploitation in the next 30 days.
arch/arm64/mm/dma-mapping.c in the Linux kernel before 4.0.3, as used in the ION subsystem in Android and other products, does not initialize certain data structures, which allows local users to obtain sensitive information from kernel memory by triggering a dma_mmap call.
Affected products
- Linux Linux Kernel: up to and including 4.0.2
Published 2016-10-10. Last modified 2026-06-17.