PT-2015-6138 · Linux+3 · Linux Kernel+3

Andrew Lutomirski

·

Published

2015-07-23

·

Updated

2024-09-27

·

CVE-2015-3290

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 4.1.6
Description The issue allows local users to gain privileges by triggering an NMI within a certain instruction window due to improper reliance on espfix64 during nested NMI processing in arch/x86/entry/entry 64.S on the x86 64 platform.
Recommendations For Linux kernel versions prior to 4.1.6, update to version 4.1.6 or later to resolve the issue.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2015-1699
ALT-PU-2015-1849
CVE-2015-3290
DSA-3313-1
OPENSUSE-SU-2015_1382-1
OPENSUSE-SU-2015_1842-1
USN-2687-1
USN-2688-1
USN-2689-1
USN-2690-1
USN-2691-1
USN-2700-1
USN-2701-1

Affected Products

Alt Linux
Linux Kernel
Suse
Ubuntu