PT-2015-7046 · Linux+3 · Linux Kernel+3

Adam Mariš

·

Published

2015-08-03

·

Updated

2020-06-02

·

CVE-2015-5707

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Linux kernel versions 2.6.x through 4.x before 4.1
Description The issue is related to an integer overflow in the sg start req function, which can be triggered by a large iov count value in a write request. This can cause a denial of service or possibly have other unspecified impacts. The estimated number of potentially affected devices is not provided.
Recommendations For Linux kernel versions 2.6.x through 4.x before 4.1, update to version 4.1 or later to resolve the issue. At the moment, there is no other information about additional mitigation measures for this specific issue.

Exploit

Fix

DoS

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2015-1678
ALT-PU-2015-1849
CVE-2015-5707
DLA-310-1
DSA-3329-1
MGASA-2015-0386
MGASA-2015-0390
MGASA-2016-0015
OPENSUSE-SU-2015_1842-1
OPENSUSE-SU-2016_0301-1
SUSE-SU-2015:1478-1
SUSE-SU-2015:1592-1
SUSE-SU-2015:1611-1
SUSE-SU-2015:1678-1
SUSE-SU-2015:2084-1
SUSE-SU-2015:2085-1
SUSE-SU-2015:2086-1
SUSE-SU-2015:2087-1
SUSE-SU-2015:2089-1
SUSE-SU-2015:2090-1
SUSE-SU-2015:2091-1
SUSE-SU-2015:2167-1
SUSE-SU-2016:0585-1
SUSE-SU-2016:0785-1
USN-2733-1
USN-2734-1
USN-2737-1
USN-2738-1
USN-2750-1
USN-2759-1
USN-2760-1

Affected Products

Alt Linux
Linux Kernel
Suse
Ubuntu