PT-2016-4009 · Linux+5 · Linux Kernel+5

Wade Mealing

·

Published

2015-11-18

·

Updated

2018-08-30

·

CVE-2015-8767

CVSS v3.1

6.2

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 4.3
Description The issue is related to the net/sctp/sm sideeffect.c file in the Linux kernel, where it does not properly manage the relationship between a lock and a socket. This allows local users to cause a denial of service, specifically a deadlock, by making a crafted sctp accept call.
Recommendations For Linux kernel versions prior to 4.3, update to version 4.3 or later to resolve the issue.

Exploit

Fix

DoS

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2015-2010
ALT-PU-2016-1485
CESA-2016_0715
CESA-2016_1277
CVE-2015-8767
DLA-412-1
DSA-3448-1
DSA-3503-1
OPENSUSE-SU-2016_0280-1
OPENSUSE-SU-2016_0301-1
OPENSUSE-SU-2016_0318-1
OPENSUSE-SU-2016_1008-1
RHSA-2016:0715
RHSA-2016:1277
RHSA-2016:1301
RHSA-2016:1341
RHSA-2016_0715
RHSA-2016_1277
RHSA-2016_1301
SUSE-SU-2016:0585-1
SUSE-SU-2016:0785-1
SUSE-SU-2016:0911-1
SUSE-SU-2016:1102-1
SUSE-SU-2016:1203-1
SUSE-SU-2016:2074-1
USN-2930-1
USN-2930-2
USN-2930-3
USN-2931-1
USN-2932-1
USN-2967-1
USN-2967-2
USN-3083-1
USN-3083-2

Affected Products

Alt Linux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu