[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2015-7312Date: (C)2015-12-15   (M)2024-02-22


Multiple race conditions in the Advanced Union Filesystem (aufs) aufs3-mmap.patch and aufs4-mmap.patch patches for the Linux kernel 3.x and 4.x allow local users to cause a denial of service (use-after-free and BUG) or possibly gain privileges via a (1) madvise or (2) msync system call, related to mm/madvise.c and mm/msync.c.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 4.4
Exploit Score: 3.4
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: LOCAL
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
DSA-3364
USN-2777-1
http://sourceforge.net/p/aufs/mailman/message/34449209/
http://www.openwall.com/lists/oss-security/2015/09/22/10

CPE    2
cpe:/o:linux:linux_kernel
cpe:/o:debian:debian_linux:8.0
CWE    1
CWE-362
OVAL    8
oval:org.secpod.oval:def:702804
oval:org.secpod.oval:def:52604
oval:org.secpod.oval:def:702798
oval:org.secpod.oval:def:52607
...

© SecPod Technologies