PT-2015-6383 · Linux+3 · Linux Kernel+3

Published

2015-06-07

·

Updated

2022-11-03

·

CVE-2015-4002

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions through 4.0.5
Description The issue allows remote attackers to cause a denial of service or possibly execute arbitrary code via a crafted packet, related to the oz usb rx and oz usb handle ep data functions. This is due to insufficiently large length values.
Recommendations For Linux kernel versions through 4.0.5, update to a version later than 4.0.5 to resolve the issue. As a temporary workaround, consider restricting access to the OZWPAN driver to minimize the risk of exploitation.

Exploit

Fix

DoS

Buffer Overflow

Weakness Enumeration

Related Identifiers

ALT-PU-2015-1564
ALT-PU-2015-1568
CVE-2015-4002
OPENSUSE-SU-2015_1382-1
OPENSUSE-SU-2016_0301-1
USN-2662-1
USN-2663-1
USN-2664-1
USN-2665-1
USN-2666-1
USN-2667-1

Affected Products

Alt Linux
Linux Kernel
Suse
Ubuntu