CVE-2015-8543

MEDIUM

Description

The networking implementation in the Linux kernel through 4.3.3, as used in Android and other products, does not validate protocol identifiers for certain protocol families, which allows local users to cause a denial of service (NULL function pointer dereference and system crash) or possibly gain privileges by leveraging CLONE_NEWUSER support to execute a crafted SOCK_RAW application.

References

http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=79462ad02e861803b3840cc782248c7359451cd9

http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00094.html

http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00045.html

http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00038.html

http://rhn.redhat.com/errata/RHSA-2016-0855.html

http://rhn.redhat.com/errata/RHSA-2016-2574.html

http://rhn.redhat.com/errata/RHSA-2016-2584.html

http://www.debian.org/security/2015/dsa-3426

http://www.debian.org/security/2016/dsa-3434

http://www.openwall.com/lists/oss-security/2015/12/09/5

http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html

http://www.securityfocus.com/bid/79698

http://www.securitytracker.com/id/1034892

http://www.ubuntu.com/usn/USN-2886-1

http://www.ubuntu.com/usn/USN-2888-1

http://www.ubuntu.com/usn/USN-2890-1

http://www.ubuntu.com/usn/USN-2890-2

http://www.ubuntu.com/usn/USN-2890-3

https://bugzilla.redhat.com/show_bug.cgi?id=1290475

https://github.com/torvalds/linux/commit/79462ad02e861803b3840cc782248c7359451cd9

Details

Source: MITRE

Published: 2015-12-28

Updated: 2018-01-05

Risk Information

CVSS v2.0

Base Score: 6.9

Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 3.4

Severity: MEDIUM

CVSS v3.0

Base Score: 7

Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 1

Severity: HIGH

Vulnerable Software

Configuration 1

OR

cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions up to 4.3.2 (inclusive)

Tenable Plugins

View all (40 total)

IDNameProductFamilySeverity
124978EulerOS Virtualization for ARM 64 3.0.1.0 : kernel (EulerOS-SA-2019-1525)NessusHuawei Local Security Checks
high
124813EulerOS Virtualization 3.0.1.0 : kernel (EulerOS-SA-2019-1489)NessusHuawei Local Security Checks
critical
99787EulerOS 2.0 SP1 : kernel (EulerOS-SA-2016-1024)NessusHuawei Local Security Checks
medium
99163OracleVM 3.3 : Unbreakable / etc (OVMSA-2017-0057) (Dirty COW)NessusOracleVM Local Security Checks
critical
95841Scientific Linux Security Update : kernel on SL7.x x86_64 (20161103)NessusScientific Linux Local Security Checks
critical
95321CentOS 7 : kernel (CESA-2016:2574)NessusCentOS Local Security Checks
critical
94697Oracle Linux 7 : kernel (ELSA-2016-2574)NessusOracle Linux Local Security Checks
critical
94547RHEL 7 : kernel-rt (RHSA-2016:2584)NessusRed Hat Local Security Checks
critical
94537RHEL 7 : kernel (RHSA-2016:2574)NessusRed Hat Local Security Checks
critical
93289SUSE SLES11 Security Update : kernel (SUSE-SU-2016:2074-1)NessusSuSE Local Security Checks
critical
92679Debian DSA-3426-1 : Linux Security UpdateNessusDebian Local Security Checks
medium
91743OracleVM 3.2 : kernel-uek (OVMSA-2016-0060)NessusOracleVM Local Security Checks
high
91643Scientific Linux Security Update : kernel on SL6.x i386/x86_64 (20160510)NessusScientific Linux Local Security Checks
medium
91295OracleVM 3.3 : kernel-uek (OVMSA-2016-0053)NessusOracleVM Local Security Checks
high
91293Oracle Linux 5 / 6 : Unbreakable Enterprise kernel (ELSA-2016-3567)NessusOracle Linux Local Security Checks
medium
91292Oracle Linux 5 / 6 : Unbreakable Enterprise kernel (ELSA-2016-3566)NessusOracle Linux Local Security Checks
medium
91291Oracle Linux 6 / 7 : Unbreakable Enterprise kernel (ELSA-2016-3565)NessusOracle Linux Local Security Checks
high
91210Oracle Linux 6 : kernel (ELSA-2016-0855)NessusOracle Linux Local Security Checks
high
91170CentOS 6 : kernel (CESA-2016:0855)NessusCentOS Local Security Checks
high
91077RHEL 6 : kernel (RHSA-2016:0855)NessusRed Hat Local Security Checks
high
90884SUSE SLES11 Security Update : kernel (SUSE-SU-2016:1203-1)NessusSuSE Local Security Checks
critical
90264SUSE SLED11 / SLES11 Security Update : kernel (SUSE-SU-2016:0911-1)NessusSuSE Local Security Checks
critical
89400Fedora 23 : kernel-4.2.8-300.fc23 (2015-c59710b05d)NessusFedora Local Security Checks
medium
89393Fedora 22 : kernel-4.2.8-200.fc22 (2015-c1c2f5e168)NessusFedora Local Security Checks
medium
89026Ubuntu 14.04 LTS : linux-lts-vivid regression (USN-2910-2)NessusUbuntu Local Security Checks
high
89022SUSE SLED12 / SLES12 Security Update : kernel (SUSE-SU-2016:0585-1)NessusSuSE Local Security Checks
high
88901Ubuntu 14.04 LTS : linux-lts-vivid vulnerabilities (USN-2910-1)NessusUbuntu Local Security Checks
high
88896Ubuntu 12.04 LTS : linux-lts-trusty vulnerabilities (USN-2907-2)NessusUbuntu Local Security Checks
high
88895Ubuntu 14.04 LTS : linux vulnerabilities (USN-2907-1)NessusUbuntu Local Security Checks
high
88605openSUSE Security Update : the Linux Kernel (openSUSE-2016-136)NessusSuSE Local Security Checks
high
88545openSUSE Security Update : the Linux Kernel (openSUSE-2016-124)NessusSuSE Local Security Checks
critical
88542openSUSE Security Update : the Linux Kernel (openSUSE-2016-116)NessusSuSE Local Security Checks
high
88526Ubuntu 15.10 : linux-raspi2 vulnerabilities (USN-2890-3)NessusUbuntu Local Security Checks
critical
88525Ubuntu 14.04 LTS : linux-lts-wily vulnerabilities (USN-2890-2)NessusUbuntu Local Security Checks
critical
88524Ubuntu 15.10 : linux vulnerabilities (USN-2890-1)NessusUbuntu Local Security Checks
critical
88521Ubuntu 14.04 LTS : linux-lts-utopic vulnerabilities (USN-2888-1)NessusUbuntu Local Security Checks
medium
88518Ubuntu 12.04 LTS : linux vulnerabilities (USN-2886-1)NessusUbuntu Local Security Checks
medium
88006SUSE SLED12 / SLES12 Security Update : kernel (SUSE-SU-2016:0168-1)NessusSuSE Local Security Checks
high
87741Debian DSA-3434-1 : linux - security updateNessusDebian Local Security Checks
medium
87738Debian DLA-378-1 : linux-2.6 security updateNessusDebian Local Security Checks
medium