CVE-2015-7292

CRITICAL

Stack-based buffer overflow in the havok_write function in drivers/staging/havok/havok.c in Amazon Fire OS before 2016-01-15 allows attackers to cause a denial of service (panic) or possibly have u...

Affects 1 product across 1 vendor.

BCS7.11
CVSS 3.09.8
EPSS1.9%
Percentile77th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-119: Improper Restriction of Operations within Memory Buffer

Parent class for buffer-related vulnerabilities where operations exceed buffer boundaries.

Related Attack Patterns (CAPEC)
CAPEC-8 Buffer Overflow in an API Call
via CWE-119
CAPEC-9 Buffer Overflow in Local Command-Line Utilities
via CWE-119
CAPEC-10 Buffer Overflow via Environment Variables
via CWE-119
CAPEC-14 Client-side Injection-induced Buffer Overflow
via CWE-119
CAPEC-24 Filter Failure through Buffer Overflow
via CWE-119
Show all 12

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

This vulnerability was disclosed in 2017. A critical vulnerability affects Amazon systems (CVE-2015-7292). No public exploit code is currently available. Isolate affected systems if patching is not feasible.

BSID: BS-2017-GLOBAL-248051-C • Model: rule-based-v1 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2015-7292?
This vulnerability was disclosed in 2017. A critical vulnerability affects Amazon systems (CVE-2015-7292). No public exploit code is currently available. Isolate affected systems if patching is not feasible.
What is the CVSS score for CVE-2015-7292?
CVE-2015-7292 has CVSS 9.8 (Critical). Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. EPSS: 1.9%.
Is CVE-2015-7292 actively exploited?
No confirmed active exploitation of CVE-2015-7292 as of 2026-05-30.
How do I remediate CVE-2015-7292?
Priority: MEDIUM.
What systems are affected by CVE-2015-7292?
CVE-2015-7292 affects: Amazon.
Vulnerability Details
CVE IDCVE-2015-7292
BSIDBS-2017-GLOBAL-248051-C BreachSpider Global ID
CVSS VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2017-04-10
Last Modified2026-05-13
ICS Relevance15%
Weakness (CWE)
Domains
CLOUD
SourceNVD
Official Description

Stack-based buffer overflow in the havok_write function in drivers/staging/havok/havok.c in Amazon Fire OS before 2016-01-15 allows attackers to cause a denial of service (panic) or possibly have unspecified other impact via a long string to /dev/hv.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

Vulnerability details: Stack-based buffer overflow in the havok_write function in drivers/staging/havok/havok.c in Amazon Fire OS before 2016-01-15 allows attackers to cause a denial of service (panic) or possibly have unspecified other impact via a long string to /dev/hv. CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.

Exploitation Likelihood: LOW

Affected Products
VendorProductFixed Version
Amazon Fire Os
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 3418 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Modelrule-based-v1
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hashd72d3f4a86d7165cbca96c36331dc80b698ea36ce53060bbeb9001c8c9b888aa2a1f2ac1c248298e71b024eb191acd8dac5b0c5c9b2a8c239f809fad947d33ec
Related CVEs affecting Amazon
CVE-2024-32888 10.0 The Amazon JDBC Driver for Redshift is a Type 4 JDBC driver that provides dat... CVE-2012-4249 10.0 The Amazon Lab126 com.lab126.system sendEvent implementation on the Kindle To... CVE-2019-3984 9.8 Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to ex... CVE-2019-18960 9.8 Firecracker vsock implementation buffer overflow in versions 0.18.0 and 0.19.... CVE-2019-3989 9.8 Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to ex...
View all Amazon CVEs →

Critical Severity - Know Your Exposure

A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →