CVE-2015-8543
Vulnerability Summary
Timeline
Description
The networking implementation in the Linux kernel through 4.3.3, as used in Android and other products, does not validate protocol identifiers for certain protocol families, which allows local users to cause a denial of service (NULL function pointer dereference and system crash) or possibly gain privileges by leveraging CLONE_NEWUSER support to execute a crafted SOCK_RAW application.
CVSS Metrics
- v3.1•HIGH•Score: 7CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- v3.0•HIGH•Score: 7CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- v2.0•MEDIUM•Score: 6.9AV:L/AC:M/Au:N/C:C/I:C/A:C
EPSS Trends
Current EPSS score: 1.22%• Percentile: 67%
Affected Systems
- debian•linux
< 4.3.3-1 | < 4.3.3-1 | < 4.3.3-1 | < 4.3.3-1
- ubuntu•linux
< 3.13.0-79.123
- ubuntu•linux-azure
all
- ubuntu•linux-azure-6.11
all
- ubuntu•linux-azure-fde
all
- ubuntu•linux-azure-fde-5.15
all
- ubuntu•linux-gcp
all
- ubuntu•linux-gcp-6.11
all
- ubuntu•linux-gke
all
- ubuntu•linux-gkeop
all
- ubuntu•linux-hwe
all
- ubuntu•linux-hwe-6.11
all
- ubuntu•linux-hwe-edge
all
- ubuntu•linux-intel-iot-realtime
all
- ubuntu•linux-lowlatency-hwe-6.11
all
- ubuntu•linux-lts-utopic
< 3.16.0-60.80~14.04.1
- ubuntu•linux-lts-vivid
< 3.19.0-51.57~14.04.1
- ubuntu•linux-lts-wily
< 4.2.0-27.32~14.04.1
- ubuntu•linux-raspi-realtime
all
- ubuntu•linux-raspi2
all
- ubuntu•linux-realtime
all | all
- ubuntu•linux-riscv
all | all | all
- linux•linux_kernel
< 3.2.75 | ≥ 3.3, < 3.4.111 | ≥ 3.5, < 3.10.95 | ≥ 3.11, < 3.12.52 | ≥ 3.13, < 3.14.59 | ≥ 3.15, < 3.16.35 | ≥ 3.17, < 3.18.26 | ≥ 3.19, < 4.1.16 | ≥ 4.2, < 4.3.4
References (34)
- http://rhn.redhat.com/errata/RHSA-2016-0855.html
- http://www.securitytracker.com/id/1034892
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- http://www.ubuntu.com/usn/USN-2886-1
- http://www.ubuntu.com/usn/USN-2890-3
- http://rhn.redhat.com/errata/RHSA-2016-2584.html
- http://rhn.redhat.com/errata/RHSA-2016-2574.html
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00045.html
- http://www.securityfocus.com/bid/79698
- http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00038.html
- http://www.ubuntu.com/usn/USN-2890-2
- https://github.com/torvalds/linux/commit/79462ad02e861803b3840cc782248c7359451cd9
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=79462ad02e861803b3840cc782248c7359451cd9
- http://www.debian.org/security/2015/dsa-3426
- http://www.openwall.com/lists/oss-security/2015/12/09/5
- http://www.ubuntu.com/usn/USN-2890-1
- https://bugzilla.redhat.com/show_bug.cgi?id=1290475
- http://www.debian.org/security/2016/dsa-3434
- http://www.ubuntu.com/usn/USN-2888-1
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00094.html
- https://ubuntu.com/security/CVE-2015-8543
- http://www.openwall.com/lists/oss-security/2015/12/09/3
- http://www.openwall.com/lists/oss-security/2015/12/11/6
- https://ubuntu.com/security/notices/USN-2886-1
- https://ubuntu.com/security/notices/USN-2886-2
- https://ubuntu.com/security/notices/USN-2888-1
- https://ubuntu.com/security/notices/USN-2890-1
- https://ubuntu.com/security/notices/USN-2890-2
- https://ubuntu.com/security/notices/USN-2890-3
- https://ubuntu.com/security/notices/USN-2910-1
- https://ubuntu.com/security/notices/USN-2907-1
- https://ubuntu.com/security/notices/USN-2907-2
- https://www.cve.org/CVERecord?id=CVE-2015-8543
- https://security-tracker.debian.org/tracker/CVE-2015-8543