7.8

CVE-2015-2686

net/socket.c in the Linux kernel 3.19 before 3.19.3 does not validate certain range data for (1) sendto and (2) recvfrom system calls, which allows local users to gain privileges by leveraging a subsystem that uses the copy_from_iter function in the iov_iter interface, as demonstrated by the Bluetooth subsystem.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LinuxLinux Kernel Version3.19
LinuxLinux Kernel Version3.19.1
LinuxLinux Kernel Version3.19.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.39% 0.301
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.19.3
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=4de930efc23b92ddf88ce91c405ee645fe6e27ea
http://grsecurity.net/~spender/viro.txt
http://twitter.com/grsecurity/statuses/579050211605102592
http://twitter.com/grsecurity/statuses/579060953477701632
http://twitter.com/grsecurity/statuses/579075689439059968
http://www.openwall.com/lists/oss-security/2015/03/23/14
http://www.securityfocus.com/bid/73286
https://bugzilla.redhat.com/show_bug.cgi?id=1205242
https://github.com/torvalds/linux/commit/4de930efc23b92ddf88ce91c405ee645fe6e27ea