[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247621

 
 

909

 
 

194512

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2015-7990Date: (C)2016-01-07   (M)2024-03-21


Race condition in the rds_sendmsg function in net/rds/sendmsg.c in the Linux kernel before 4.3.3 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by using a socket that was not properly bound. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-6937.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 5.8CVSS Score : 5.9
Exploit Score: 1.0Exploit Score: 3.4
Impact Score: 4.7Impact Score: 8.5
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: LOCALAccess Vector: LOCAL
Attack Complexity: HIGHAccess Complexity: MEDIUM
Privileges Required: LOWAuthentication: NONE
User Interaction: NONEConfidentiality: PARTIAL
Scope: UNCHANGEDIntegrity: PARTIAL
Confidentiality: LOWAvailability: COMPLETE
Integrity: LOW 
Availability: HIGH 
  
Reference:
SECTRACK-1034453
BID-77340
DSA-3396
SUSE-SU-2015:2108
SUSE-SU-2015:2194
SUSE-SU-2015:2292
SUSE-SU-2015:2339
SUSE-SU-2015:2350
SUSE-SU-2016:0335
SUSE-SU-2016:0337
SUSE-SU-2016:0354
SUSE-SU-2016:0380
SUSE-SU-2016:0381
SUSE-SU-2016:0383
SUSE-SU-2016:0384
SUSE-SU-2016:0386
SUSE-SU-2016:0387
SUSE-SU-2016:0434
SUSE-SU-2016:2074
USN-2886-1
USN-2887-1
USN-2887-2
USN-2888-1
USN-2889-1
USN-2889-2
USN-2890-1
USN-2890-2
USN-2890-3
https://lkml.org/lkml/2015/10/16/530
http://www.openwall.com/lists/oss-security/2015/10/27/5
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=8c7188b23474cca017b3ef354c4a58456f68303a
http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.3.3
http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
https://bugzilla.redhat.com/show_bug.cgi?id=1276437
https://bugzilla.suse.com/show_bug.cgi?id=952384
https://github.com/torvalds/linux/commit/8c7188b23474cca017b3ef354c4a58456f68303a
openSUSE-SU-2015:2232

CPE    1
cpe:/o:linux:linux_kernel
CWE    1
CWE-362
OVAL    20
oval:org.secpod.oval:def:109921
oval:org.secpod.oval:def:109734
oval:org.secpod.oval:def:702960
oval:org.secpod.oval:def:52690
...

© SecPod Technologies