CVE-2014-9892 is a sensitive information disclosure vulnerability affecting the Linux kernel (through version 4.7) and Android devices, specifically Nexus 5 and 7 (2013) before August 5, 2016. The flaw resides in the snd_compr_tstamp function, which fails to properly initialize a timestamp data structure. This allows an attacker to obtain sensitive information through a specially crafted application. The vulnerability has a CVSS v3 score of 5.5 (Medium), indicating a local attack vector with low attack complexity, requiring user interaction (e.g., installing a malicious app), and resulting in high confidentiality impact. There is no integrity or availability impact. There is no evidence of active exploitation, nor are there any known public exploit codes available in Metasploit, Nuclei, or ExploitDB. The vulnerability has received minimal community attention, with no social media mentions or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 6.0.1CPE matchmatch criteria | cpe:2.3:o:google:android:*:*:*:*:*:*:*:* | ||
<= 4.7CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.