CVE-2015-1805

Advisory lineage Upstream: 0 Downstream: 26
Modified
Published: 08 Aug 2015, 10:00
Last modified:06 Aug 2024, 04:54

Vulnerability Summary

Overall Risk (default)
medium
31/100
CVSS Score
7.2 HIGH
v2.0 (nvd)
EPSS Score
9.01% LOW
9% probability -6.02%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

08 Aug 2015, 10:00
Published
Vulnerability first disclosed
06 Aug 2024, 04:54
Last Modified
Vulnerability information updated

Description

The (1) pipe_read and (2) pipe_write implementations in fs/pipe.c in the Linux kernel before 3.16 do not properly consider the side effects of failed __copy_to_user_inatomic and __copy_from_user_inatomic calls, which allows local users to cause a denial of service (system crash) or possibly gain privileges via a crafted application, aka an "I/O vector array overrun."

CVSS Metrics

  • v2.0HIGHScore: 7.2AV:L/AC:L/Au:N/C:C/I:C/A:C

EPSS Trends

Current EPSS score: 9.01% Percentile: 93%

Techniques & Countermeasures

  • CWE-17DEPRECATED: Code

    This entry has been deprecated. It was originally used for organizing the Development View (CWE-699) and some other views, but it introduced unnecessary complexity and depth to the resulting tree.

Affected Systems

  • googleandroid

    4.4.3 | 5.0.1 | 5.1 | 5.1.1 | 6.0

  • linuxlinux_kernel

    ≤ 3.15.10

References (36)