CVE-2015-1805

Aliases:UBUNTU-CVE-2015-1805DEBIAN-CVE-2015-1805
Advisory lineage Upstream: 0 Downstream: 26
Modified
Published: 08 Aug 2015, 10:00
Last modified:06 Aug 2024, 04:54

Vulnerability Summary

Overall Risk (default)
medium
29/100
CVSS Score
7.2 HIGH
v2.0 (nvd)
EPSS Score
1.4% LOW
1% probability -13.64%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

08 Aug 2015, 10:00
Published
Vulnerability first disclosed
06 Aug 2024, 04:54
Last Modified
Vulnerability information updated

Description

The (1) pipe_read and (2) pipe_write implementations in fs/pipe.c in the Linux kernel before 3.16 do not properly consider the side effects of failed __copy_to_user_inatomic and __copy_from_user_inatomic calls, which allows local users to cause a denial of service (system crash) or possibly gain privileges via a crafted application, aka an "I/O vector array overrun."

CVSS Metrics

  • v2.0HIGHScore: 7.2AV:L/AC:L/Au:N/C:C/I:C/A:C

EPSS Trends

Current EPSS score: 1.40% Percentile: 71%

Techniques & Countermeasures

  • CWE-17DEPRECATED: Code

    This entry has been deprecated. It was originally used for organizing the Development View (CWE-699) and some other views, but it introduced unnecessary complexity and depth to the resulting tree.

Affected Systems

  • debianlinux

    < 3.16.2-2 | < 3.16.2-2 | < 3.16.2-2 | < 3.16.2-2

  • ubuntulinux

    < 3.13.0-58.97

  • ubuntulinux-azure

    all

  • ubuntulinux-azure-6.11

    all

  • ubuntulinux-azure-fde

    all

  • ubuntulinux-azure-fde-5.15

    all

  • ubuntulinux-gcp

    all

  • ubuntulinux-gcp-6.11

    all

  • ubuntulinux-gke

    all

  • ubuntulinux-gkeop

    all

  • ubuntulinux-hwe

    all

  • ubuntulinux-hwe-6.11

    all

  • ubuntulinux-hwe-edge

    all

  • ubuntulinux-intel-iot-realtime

    all

  • ubuntulinux-lowlatency-hwe-6.11

    all

  • ubuntulinux-raspi-realtime

    all

  • ubuntulinux-raspi2

    all

  • ubuntulinux-realtime

    all | all

  • ubuntulinux-riscv

    all | all | all

  • googleandroid

    4.4.3 | 5.0.1 | 5.1 | 5.1.1 | 6.0

  • linuxlinux_kernel

    ≤ 3.15.10

References (45)