CVE-2015-0275

medium
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

The ext4_zero_range function in fs/ext4/extents.c in the Linux kernel before 4.1 allows local users to cause a denial of service (BUG) via a crafted fallocate zero-range request.

References

http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=0f2af21aae11972fa924374ddcf52e88347cf5a8

http://rhn.redhat.com/errata/RHSA-2015-1778.html

http://rhn.redhat.com/errata/RHSA-2015-1787.html

http://www.openwall.com/lists/oss-security/2015/02/23/14

http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html

http://www.securityfocus.com/bid/75139

http://www.securitytracker.com/id/1034454

http://www.spinics.net/lists/linux-ext4/msg47193.html

https://bugzilla.redhat.com/show_bug.cgi?id=1193907

https://github.com/torvalds/linux/commit/0f2af21aae11972fa924374ddcf52e88347cf5a8

https://support.f5.com/csp/article/K05211147

Details

Source: MITRE

Published: 2015-10-19

Updated: 2019-12-27

Type: CWE-17

Risk Information

CVSS v2

Base Score: 4.9

Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C

Impact Score: 6.9

Exploitability Score: 3.9

Severity: MEDIUM

Vulnerable Software

Configuration 1

OR

cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions up to 4.0.5 (inclusive)

Configuration 2

OR

cpe:2.3:o:oracle:linux:7:*:*:*:*:*:*:*

Tenable Plugins

View all (15 total)

IDNameProductFamilySeverity
124977EulerOS Virtualization for ARM 64 3.0.1.0 : kernel (EulerOS-SA-2019-1524)NessusHuawei Local Security Checks
high
124809EulerOS Virtualization 3.0.1.0 : kernel (EulerOS-SA-2019-1485)NessusHuawei Local Security Checks
high
86702RHEL 7 : kernel (RHSA-2015:1778)NessusRed Hat Local Security Checks
high
86511CentOS 7 : kernel (CESA-2015:1778)NessusCentOS Local Security Checks
high
85980RHEL 7 : kernel-rt (RHSA-2015:1788)NessusRed Hat Local Security Checks
high
85979RHEL 6 : kernel-rt (RHSA-2015:1787)NessusRed Hat Local Security Checks
high
85960Scientific Linux Security Update : kernel on SL7.x x86_64 (20150915)NessusScientific Linux Local Security Checks
high
85958Oracle Linux 7 : kernel (ELSA-2015-1778)NessusOracle Linux Local Security Checks
high
84125Ubuntu 15.04 : linux vulnerabilities (USN-2638-1)NessusUbuntu Local Security Checks
high
84124Ubuntu 14.10 : linux vulnerabilities (USN-2637-1)NessusUbuntu Local Security Checks
medium
84123Ubuntu 14.04 LTS : linux-lts-vivid vulnerabilities (USN-2636-1)NessusUbuntu Local Security Checks
high
84122Ubuntu 14.04 LTS : linux-lts-utopic vulnerabilities (USN-2635-1)NessusUbuntu Local Security Checks
medium
82756openSUSE Security Update : Linux Kernel (openSUSE-2015-302)NessusSuSE Local Security Checks
critical
81863Fedora 20 : kernel-3.18.9-100.fc20 (2015-3594)NessusFedora Local Security Checks
critical
81717Fedora 21 : kernel-3.18.8-201.fc21 (2015-3011)NessusFedora Local Security Checks
critical