CVE-2015-1420
Advisory lineage Upstream: 0 Downstream: 12
Modified
Published: 16 Mar 2015, 10:00
Last modified:06 Aug 2024, 04:40
Vulnerability Summary
Overall Risk (default)
minimal
8/100 CVSS Score
1.9 LOW
v2.0 (nvd)
EPSS Score
0.03% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
16 Mar 2015, 10:00
Published
Vulnerability first disclosed
06 Aug 2024, 04:40
Last Modified
Vulnerability information updated
Description
Race condition in the handle_to_path function in fs/fhandle.c in the Linux kernel through 3.19.1 allows local users to bypass intended size restrictions and trigger read operations on additional memory locations by changing the handle_bytes value of a file handle during the execution of this function.
CVSS Metrics
- v2.0•LOW•Score: 1.9AV:L/AC:M/Au:N/C:P/I:N/A:N
EPSS Trends
Current EPSS score: 0.03%• Percentile: 8%
Techniques & Countermeasures
- CWE-362•Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.
Affected Systems
- debian•debian_linux
7.0
- linux•linux_kernel
≤ 3.18.9
References (14)
- http://www.debian.org/security/2015/dsa-3170
- http://www.ubuntu.com/usn/USN-2660-1
- http://www.openwall.com/lists/oss-security/2015/01/29/12
- http://www.ubuntu.com/usn/USN-2665-1
- http://marc.info/?l=linux-kernel&m=142247707318982&w=2
- http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00021.html
- http://www.ubuntu.com/usn/USN-2661-1
- http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00011.html
- https://bugzilla.redhat.com/show_bug.cgi?id=1187534
- http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00004.html
- http://www.securityfocus.com/bid/72357
- http://www.ubuntu.com/usn/USN-2667-1
- http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00023.html
- http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00018.html