Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-8963

Опубликовано: 06 янв. 2016
Источник: redhat
CVSS3: 7
EPSS Низкий

Описание

Race condition in kernel/events/core.c in the Linux kernel before 4.4 allows local users to gain privileges or cause a denial of service (use-after-free) by leveraging incorrect handling of an swevent data structure during a CPU unplug operation.

Race condition in kernel/events/core.c in the Linux kernel before 4.4 allows local users to gain privileges or cause a denial of service via use-after-free vulnerability by leveraging incorrect handling of an swevent data structure during a CPU unplug operation.

Отчет

This issue affects the Linux kernel shipping with Red Hat Enterprise Linux 6. Future updates for the respective releases may address the issue. This issue does not not affect Red Hat Enterprise Linux 5, 7, MRG-2 kernels. This has been rated as having Moderate security impact and is not currently planned to be addressed in future updates of Red Hat Enterprise Linux 5. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.

Меры по смягчению последствий

A possible mitigation is to only remove CPU's while the system is shut down. This will prevent local attackers from being able to abuse this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kernelNot affected
Red Hat Enterprise Linux 6kernelAffected
Red Hat Enterprise Linux 7kernelNot affected
Red Hat Enterprise Linux 7kernel-rtNot affected
Red Hat Enterprise MRG 2realtime-kernelNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=1411245kernel: Race condition on CPU unplug leading to use-after-free

EPSS

Процентиль: 26%
0.00091
Низкий

7 High

CVSS3

Связанные уязвимости

CVSS3: 7
ubuntu
около 9 лет назад

Race condition in kernel/events/core.c in the Linux kernel before 4.4 allows local users to gain privileges or cause a denial of service (use-after-free) by leveraging incorrect handling of an swevent data structure during a CPU unplug operation.

CVSS3: 7
nvd
около 9 лет назад

Race condition in kernel/events/core.c in the Linux kernel before 4.4 allows local users to gain privileges or cause a denial of service (use-after-free) by leveraging incorrect handling of an swevent data structure during a CPU unplug operation.

CVSS3: 7
debian
около 9 лет назад

Race condition in kernel/events/core.c in the Linux kernel before 4.4 ...

CVSS3: 7
github
больше 3 лет назад

Race condition in kernel/events/core.c in the Linux kernel before 4.4 allows local users to gain privileges or cause a denial of service (use-after-free) by leveraging incorrect handling of an swevent data structure during a CPU unplug operation.

suse-cvrf
около 9 лет назад

Security update for the Linux Kernel

EPSS

Процентиль: 26%
0.00091
Низкий

7 High

CVSS3