PT-2015-5825 · Linux+5 · Linux Kernel+5

Quentin Casasnovas

·

Publicado

2015-03-25

·

Atualizado

2024-03-14

·

CVE-2015-2666

CVSS v2.0

6.9

Média

VetorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 4.0
Description The issue is a stack-based buffer overflow in the get matching model microcode function, located in arch/x86/kernel/cpu/microcode/intel early.c. This allows context-dependent attackers to gain privileges by constructing a crafted microcode header and leveraging root privileges for write access to the initrd.
Recommendations For Linux kernel versions prior to 4.0, update to version 4.0 or later to resolve the issue. As a temporary workaround, consider restricting root privileges to minimize the risk of exploitation.

Exploit

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2015-1485
ALT-PU-2015-1849
CESA-2015_1534
CVE-2015-2666
OPENSUSE-SU-2016_0301-1
RHSA-2015:1534
RHSA-2015:1565
RHSA-2015_1534
RHSA-2015_1565
SUSE-SU-2015:1071-1
USN-2587-1
USN-2588-1
USN-2589-1
USN-2590-1

Produtos afetados

Alt Linux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu