Integer overflow in the sg_start_req function in drivers/scsi/sg.c in the Linux kernel 2.6.x through 4.x before 4.1 allows local users to cause a denial of service or possibly have unspecified other impact via a large iov_count value in a write request.
http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00004.html
http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00018.html
http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00021.html
http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00026.html
http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00027.html
http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00028.html
http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00029.html
http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00030.html
http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00031.html
http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00032.html
http://www.debian.org/security/2015/dsa-3329
http://www.openwall.com/lists/oss-security/2015/08/01/6
http://www.securityfocus.com/bid/76145
http://www.securitytracker.com/id/1033521
http://www.ubuntu.com/usn/USN-2733-1
http://www.ubuntu.com/usn/USN-2734-1
http://www.ubuntu.com/usn/USN-2737-1
http://www.ubuntu.com/usn/USN-2738-1
http://www.ubuntu.com/usn/USN-2750-1
http://www.ubuntu.com/usn/USN-2759-1
http://www.ubuntu.com/usn/USN-2760-1
https://bugzilla.redhat.com/show_bug.cgi?id=1250030
https://github.com/torvalds/linux/commit/451a2886b6bf90e2fb378f7c46c655450fb96e81
https://github.com/torvalds/linux/commit/fdc81f45e9f57858da6351836507fbcf1b7583ee
OR
OR
cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*
OR
OR
cpe:2.3:o:suse:suse_linux_enterprise_desktop:11:sp3:*:*:*:*:*:*
cpe:2.3:o:suse:suse_linux_enterprise_server:11:sp2:*:*:ltss:*:*:*
cpe:2.3:o:suse:suse_linux_enterprise_server:11:sp3:*:*:*:*:*:*
cpe:2.3:o:suse:suse_linux_enterprise_server:11:sp3:*:*:*:vmware:*:*
ID | Name | Product | Family | Severity |
---|---|---|---|---|
124812 | EulerOS Virtualization 3.0.1.0 : kernel (EulerOS-SA-2019-1488) | Nessus | Huawei Local Security Checks | high |
100238 | OracleVM 3.2 : Unbreakable / etc (OVMSA-2017-0106) | Nessus | OracleVM Local Security Checks | critical |
100235 | Oracle Linux 6 : Unbreakable Enterprise kernel (ELSA-2017-3567) | Nessus | Oracle Linux Local Security Checks | critical |
99164 | OracleVM 3.2 : Unbreakable / etc (OVMSA-2017-0058) | Nessus | OracleVM Local Security Checks | high |
99163 | OracleVM 3.3 : Unbreakable / etc (OVMSA-2017-0057) (Dirty COW) | Nessus | OracleVM Local Security Checks | critical |
99161 | Oracle Linux 6 : Unbreakable Enterprise kernel (ELSA-2017-3535) | Nessus | Oracle Linux Local Security Checks | high |
99160 | Oracle Linux 6 / 7 : Unbreakable Enterprise kernel (ELSA-2017-3534) | Nessus | Oracle Linux Local Security Checks | high |
89993 | SUSE SLED12 / SLES12 Security Update : kernel (SUSE-SU-2016:0785-1) | Nessus | SuSE Local Security Checks | critical |
89022 | SUSE SLED12 / SLES12 Security Update : kernel (SUSE-SU-2016:0585-1) | Nessus | SuSE Local Security Checks | high |
88545 | openSUSE Security Update : the Linux Kernel (openSUSE-2016-124) | Nessus | SuSE Local Security Checks | critical |
86668 | openSUSE Security Update : the Linux Kernel (openSUSE-2015-686) | Nessus | SuSE Local Security Checks | high |
86290 | SUSE SLED11 / SLES11 Security Update : kernel-source (SUSE-SU-2015:1678-1) | Nessus | SuSE Local Security Checks | high |
86244 | Ubuntu 12.04 LTS : linux vulnerabilities (USN-2759-1) | Nessus | Ubuntu Local Security Checks | medium |
86205 | Ubuntu 14.04 LTS : linux-lts-utopic vulnerability (USN-2750-1) | Nessus | Ubuntu Local Security Checks | medium |
86121 | SUSE SLED11 / SLES11 Security Update : kernel (SUSE-SU-2015:1611-1) | Nessus | SuSE Local Security Checks | high |
86049 | Debian DLA-310-1 : linux-2.6 security update | Nessus | Debian Local Security Checks | high |
85875 | Ubuntu 15.04 : linux vulnerability (USN-2738-1) | Nessus | Ubuntu Local Security Checks | medium |
85874 | Ubuntu 14.04 LTS : linux-lts-vivid vulnerability (USN-2737-1) | Nessus | Ubuntu Local Security Checks | medium |
85801 | Ubuntu 14.04 LTS : linux vulnerability (USN-2734-1) | Nessus | Ubuntu Local Security Checks | medium |
85800 | Ubuntu 12.04 LTS : linux-lts-trusty vulnerability (USN-2733-1) | Nessus | Ubuntu Local Security Checks | medium |
85764 | SUSE SLES11 Security Update : kernel (SUSE-SU-2015:1478-1) | Nessus | SuSE Local Security Checks | critical |
85281 | Debian DSA-3329-1 : linux - security update | Nessus | Debian Local Security Checks | high |