PT-2016-3560 · Linux+1 · Linux Kernel+1

Published

2015-02-17

·

Updated

2021-05-28

·

CVE-2015-0571

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions 3.x and 4.x
Description The issue is related to the WLAN driver for the Linux kernel, which does not properly verify authorization for certain private SET IOCTL calls. This allows attackers to potentially gain privileges by using a crafted application. The problem is associated with specific files, namely wlan hdd hostapd.c and wlan hdd wext.c.
Recommendations For Linux kernel versions 3.x and 4.x, update to a version that includes the necessary patches to verify authorization for private SET IOCTL calls. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2015-1186
ALT-PU-2019-1437
ALT-PU-2019-1506
ALT-PU-2020-1198
ALT-PU-2020-1501
ALT-PU-2020-2410
ALT-PU-2020-2433
ALT-PU-2021-1870
CVE-2015-0571

Affected Products

Alt Linux
Linux Kernel