PT-2015-6787 · Linux+5 · Linux Kernel+5

Jason Wang

+1

·

Published

2015-08-06

·

Updated

2023-02-12

·

CVE-2015-5156

CVSS v2.0

6.1

Medium

VectorAV:A/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 4.2
Description The issue is related to the virtnet probe function in the Linux kernel, which fails to properly allocate memory when supporting the FRAGLIST feature. This allows guest OS users to cause a denial of service by sending a crafted sequence of fragmented packets, resulting in a buffer overflow and memory corruption.
Recommendations For Linux kernel versions prior to 4.2, update to version 4.2 or later to resolve the issue.

Exploit

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2015-1834
ALT-PU-2015-1922
CESA-2015_1978
CESA-2016_0855
CVE-2015-5156
DLA-310-1
DSA-3364-1
MGASA-2015-0450
MGASA-2016-0014
MGASA-2016-0015
RHSA-2015:1977
RHSA-2015:1978
RHSA-2015_1977
RHSA-2015_1978
RHSA-2016:0855
RHSA-2016_0855
SUSE-SU-2015:1727-1
SUSE-SU-2015:2292-1
SUSE-SU-2015_1727-1
SUSE-SU-2018:1080-1
SUSE-SU-2018:1172-1
SUSE-SU-2018:1309-1
USN-2773-1
USN-2774-1
USN-2775-1
USN-2776-1
USN-2777-1
USN-2778-1
USN-2779-1

Affected Products

Alt Linux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu