Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-8019

Опубликовано: 02 мая 2016
Источник: debian
EPSS Низкий

Описание

The skb_copy_and_csum_datagram_iovec function in net/core/datagram.c in the Linux kernel 3.14.54 and 3.18.22 does not accept a length argument, which allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact via a write system call followed by a recvmsg system call.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
linuxnot-affectedpackage
linux-2.6not-affectedpackage

Примечания

  • https://www.openwall.com/lists/oss-security/2015/10/27/11

  • Only for all stable kernels before v3.19 which have backported commit

  • https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=89c22d8c3b278212eef6a8cc66b570bc840a6f5a

  • but are lacking the ioviter conversion.

EPSS

Процентиль: 15%
0.00048
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 10 лет назад

The skb_copy_and_csum_datagram_iovec function in net/core/datagram.c in the Linux kernel 3.14.54 and 3.18.22 does not accept a length argument, which allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact via a write system call followed by a recvmsg system call.

redhat
больше 10 лет назад

The skb_copy_and_csum_datagram_iovec function in net/core/datagram.c in the Linux kernel 3.14.54 and 3.18.22 does not accept a length argument, which allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact via a write system call followed by a recvmsg system call.

CVSS3: 7.8
nvd
почти 10 лет назад

The skb_copy_and_csum_datagram_iovec function in net/core/datagram.c in the Linux kernel 3.14.54 and 3.18.22 does not accept a length argument, which allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact via a write system call followed by a recvmsg system call.

CVSS3: 7.8
github
больше 3 лет назад

The skb_copy_and_csum_datagram_iovec function in net/core/datagram.c in the Linux kernel 3.14.54 and 3.18.22 does not accept a length argument, which allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact via a write system call followed by a recvmsg system call.

suse-cvrf
больше 9 лет назад

Security update for Linux Kernel Live Patch 2 for SLE 12 SP1

EPSS

Процентиль: 15%
0.00048
Низкий