CVE-2015-1805

HIGH
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

The (1) pipe_read and (2) pipe_write implementations in fs/pipe.c in the Linux kernel before 3.16 do not properly consider the side effects of failed __copy_to_user_inatomic and __copy_from_user_inatomic calls, which allows local users to cause a denial of service (system crash) or possibly gain privileges via a crafted application, aka an "I/O vector array overrun."

References

http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=637b58c2887e5e57850865839cc75f59184b23d1

http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=f0d1bec9d58d4c038d0ac958c9af82be6eb18045

http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00023.html

http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00049.html

http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00004.html

http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00007.html

http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00008.html

http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00009.html

http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00010.html

http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00011.html

http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00018.html

http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00021.html

http://rhn.redhat.com/errata/RHSA-2015-1042.html

http://rhn.redhat.com/errata/RHSA-2015-1081.html

http://rhn.redhat.com/errata/RHSA-2015-1082.html

http://rhn.redhat.com/errata/RHSA-2015-1120.html

http://rhn.redhat.com/errata/RHSA-2015-1137.html

http://rhn.redhat.com/errata/RHSA-2015-1138.html

http://rhn.redhat.com/errata/RHSA-2015-1190.html

http://rhn.redhat.com/errata/RHSA-2015-1199.html

http://rhn.redhat.com/errata/RHSA-2015-1211.html

http://source.android.com/security/bulletin/2016-04-02.html

http://source.android.com/security/bulletin/2016-05-01.html

http://www.debian.org/security/2015/dsa-3290

http://www.openwall.com/lists/oss-security/2015/06/06/2

http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html

http://www.securityfocus.com/bid/74951

http://www.securitytracker.com/id/1032454

http://www.ubuntu.com/usn/USN-2679-1

http://www.ubuntu.com/usn/USN-2680-1

http://www.ubuntu.com/usn/USN-2681-1

http://www.ubuntu.com/usn/USN-2967-1

http://www.ubuntu.com/usn/USN-2967-2

https://bugzilla.redhat.com/show_bug.cgi?id=1202855

https://github.com/torvalds/linux/commit/637b58c2887e5e57850865839cc75f59184b23d1

https://github.com/torvalds/linux/commit/f0d1bec9d58d4c038d0ac958c9af82be6eb18045

Details

Source: MITRE

Published: 2015-08-08

Updated: 2018-01-05

Type: CWE-17

Risk Information

CVSS v2

Base Score: 7.2

Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 3.9

Severity: HIGH

Tenable Plugins

View all (43 total)

IDNameProductFamilySeverity
124814EulerOS Virtualization for ARM 64 3.0.1.0 : kernel (EulerOS-SA-2019-1490)NessusHuawei Local Security Checks
medium
124811EulerOS Virtualization 3.0.1.0 : kernel (EulerOS-SA-2019-1487)NessusHuawei Local Security Checks
high
99163OracleVM 3.3 : Unbreakable / etc (OVMSA-2017-0057) (Dirty COW)NessusOracleVM Local Security Checks
critical
93255F5 Networks BIG-IP : Linux kernel vulnerability (K08440897)NessusF5 Networks Local Security Checks
medium
91089Ubuntu 12.04 LTS : linux-lts-trusty vulnerabilities (USN-2968-2)NessusUbuntu Local Security Checks
high
91088Ubuntu 14.04 LTS : linux vulnerabilities (USN-2968-1)NessusUbuntu Local Security Checks
high
91087Ubuntu 12.04 LTS : linux vulnerabilities (USN-2967-1)NessusUbuntu Local Security Checks
critical
90988OracleVM 3.3 : kernel-uek (OVMSA-2016-0046)NessusOracleVM Local Security Checks
medium
90178Oracle Linux 6 / 7 : Unbreakable Enterprise kernel (ELSA-2016-3528)NessusOracle Linux Local Security Checks
medium
90144Scientific Linux Security Update : kernel on SL6.x i386/x86_64 (20160323)NessusScientific Linux Local Security Checks
medium
86882OracleVM 3.3 : kernel-uek (OVMSA-2015-0147)NessusOracleVM Local Security Checks
high
86881Oracle Linux 6 / 7 : Unbreakable Enterprise kernel (ELSA-2015-3098)NessusOracle Linux Local Security Checks
high
86449F5 Networks BIG-IP : Linux kernel vulnerability (SOL17458)NessusF5 Networks Local Security Checks
high
86290SUSE SLED11 / SLES11 Security Update : kernel-source (SUSE-SU-2015:1678-1)NessusSuSE Local Security Checks
high
86121SUSE SLED11 / SLES11 Security Update : kernel (SUSE-SU-2015:1611-1)NessusSuSE Local Security Checks
high
85764SUSE SLES11 Security Update : kernel (SUSE-SU-2015:1478-1)NessusSuSE Local Security Checks
medium
85180SUSE SLED12 / SLES12 Security Update : SUSE Linux Enterprise 12 kernel (SUSE-SU-2015:1324-1)NessusSuSE Local Security Checks
high
85097Oracle Linux 6 : kernel (ELSA-2015-1272)NessusOracle Linux Local Security Checks
high
84982Ubuntu 14.04 LTS : linux vulnerabilities (USN-2681-1)NessusUbuntu Local Security Checks
high
84981Ubuntu 12.04 LTS : linux-lts-trusty vulnerabilities (USN-2680-1)NessusUbuntu Local Security Checks
high
84980Ubuntu 12.04 LTS : linux vulnerabilities (USN-2678-1)NessusUbuntu Local Security Checks
high
84925Amazon Linux AMI : kernel (ALAS-2015-565)NessusAmazon Linux Local Security Checks
high
84610RHEL 6 : kernel (RHSA-2015:1211)NessusRed Hat Local Security Checks
high
84536Scientific Linux Security Update : kernel on SL7.x x86_64 (20150623)NessusScientific Linux Local Security Checks
medium
84486RHEL 6 : kernel (RHSA-2015:1199)NessusRed Hat Local Security Checks
high
84422RHEL 5 : kernel (RHSA-2015:1190)NessusRed Hat Local Security Checks
high
84358RHEL 7 : kernel-rt (RHSA-2015:1139)NessusRed Hat Local Security Checks
medium
84357RHEL 6 : MRG (RHSA-2015:1138)NessusRed Hat Local Security Checks
medium
84356RHEL 7 : kernel (RHSA-2015:1137)NessusRed Hat Local Security Checks
medium
84352Oracle Linux 7 : kernel (ELSA-2015-1137)NessusOracle Linux Local Security Checks
medium
84346CentOS 7 : kernel (CESA-2015:1137)NessusCentOS Local Security Checks
medium
84277Debian DSA-3290-1 : linux - security updateNessusDebian Local Security Checks
high
84252Debian DLA-246-2 : linux-2.6 regression updateNessusDebian Local Security Checks
high
84225RHEL 5 : kernel (RHSA-2015:1120)NessusRed Hat Local Security Checks
high
84091CentOS 6 : kernel (CESA-2015:1081)NessusCentOS Local Security Checks
high
84078Scientific Linux Security Update : kernel on SL6.x i386/x86_64 (20150609)NessusScientific Linux Local Security Checks
high
84076RHEL 6 : kernel (RHSA-2015:1082)NessusRed Hat Local Security Checks
critical
84075RHEL 6 : kernel (RHSA-2015:1081)NessusRed Hat Local Security Checks
high
84073Oracle Linux 6 : kernel (ELSA-2015-1081)NessusOracle Linux Local Security Checks
high
83985Oracle Linux 5 : kernel (ELSA-2015-1042)NessusOracle Linux Local Security Checks
high
83979CentOS 5 : kernel (CESA-2015:1042)NessusCentOS Local Security Checks
high
83969Scientific Linux Security Update : kernel on SL5.x i386/x86_64 (20150602)NessusScientific Linux Local Security Checks
high
83968RHEL 5 : kernel (RHSA-2015:1042)NessusRed Hat Local Security Checks
high