PT-2015-3415 · Linux+5 · Linux Kernel+5

Wen Xu

·

Published

2015-05-02

·

Updated

2025-09-29

·

CVE-2015-3636

CVSS v2.0

4.9

Medium

VectorAV:L/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 4.0.3
Description The issue is related to the ping unhash function in the Linux kernel, which does not properly initialize a list data structure during an unhash operation. This can be exploited by local users to gain privileges or cause a denial of service, resulting in a use-after-free condition and potentially a system crash. The exploitation involves making a SOCK DGRAM socket system call for the IPPROTO ICMP or IPPROTO ICMPV6 protocol, followed by a connect system call after a disconnect.
Recommendations For Linux kernel versions prior to 4.0.3, update to version 4.0.3 or later to resolve the issue. As a temporary workaround, consider restricting the ability to make SOCK DGRAM socket system calls for the IPPROTO ICMP or IPPROTO ICMPV6 protocol to minimize the risk of exploitation.

Exploit

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2015-1485
ALT-PU-2015-1849
BDU:2022-00886
CESA-2015_1221
CESA-2015_1534
CVE-2015-3636
DSA-3290-1
ELSA-2015-1221
ELSA-2015-1534
ELSA-2015-3048
ELSA-2015-3049
MGASA-2015-0210
MGASA-2015-0219
MGASA-2015-0221
OPENSUSE-SU-2015_1382-1
OPENSUSE-SU-2016_0301-1
RHSA-2015:1221
RHSA-2015:1534
RHSA-2015:1564
RHSA-2015:1565
RHSA-2015:1583
RHSA-2015:1643
RHSA-2015_1221
RHSA-2015_1534
RHSA-2015_1565
SUSE-RU-2015:0621-1
SUSE-SU-2015:0581-1
SUSE-SU-2015:0736-1
SUSE-SU-2015:1071-1
SUSE-SU-2015:1174-1
SUSE-SU-2015:1224-1
SUSE-SU-2015:1376-1
SUSE-SU-2015:1478-1
SUSE-SU-2015:1487-1
SUSE-SU-2015:1488-1
SUSE-SU-2015:1489-1
SUSE-SU-2015:1491-1
SUSE-SU-2015_1071-1
USN-2631-1
USN-2632-1
USN-2633-1
USN-2634-1
USN-2635-1
USN-2636-1
USN-2637-1
USN-2638-1

Affected Products

Alt Linux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu