PT-2015-5921 · Linux+5 · Linux Kernel+5

Vasyl Kaigorodov

·

Published

2015-03-19

·

Updated

2018-01-05

·

CVE-2015-2830

CVSS v2.0

1.9

Low

VectorAV:L/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 3.19.2
Description The issue allows local users to potentially bypass the seccomp or audit protection mechanism. This could be achieved through a crafted application that utilizes specific system calls, such as the fork or close system call. The estimated number of potentially affected devices worldwide is not specified. There is no information provided about real-world incidents where this issue was exploited.
Recommendations For Linux kernel versions prior to 3.19.2, update to version 3.19.2 or later to resolve the issue. As a temporary workaround, consider restricting the use of the fork and close system calls to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2015-1291
ALT-PU-2015-1849
CESA-2015_1137
CESA-2015_1221
CVE-2015-2830
DLA-246-1
DSA-3237-1
MGASA-2015-0171
MGASA-2015-0172
MGASA-2015-0219
OPENSUSE-SU-2016_0301-1
RHSA-2015:1137
RHSA-2015:1138
RHSA-2015:1139
RHSA-2015:1221
RHSA-2015_1137
RHSA-2015_1139
RHSA-2015_1221
SUSE-RU-2015:0621-1
SUSE-SU-2015:0581-1
SUSE-SU-2015:0736-1
SUSE-SU-2015:1071-1
SUSE-SU-2015:1174-1
SUSE-SU-2015:1376-1
SUSE-SU-2015:1478-1
SUSE-SU-2015:1592-1
SUSE-SU-2015:1611-1
SUSE-SU-2015:1678-1
USN-2589-1
USN-2590-1
USN-2613-1
USN-2614-1
USN-2631-1
USN-2632-1

Affected Products

Alt Linux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu