CVE-2015-5707
MEDIUM severity · CVSS 4.6 · Integer overflow
4.6CVSS MEDIUM
Summary
Integer overflow in the sg_start_req function in drivers/scsi/sg.c in the Linux kernel 2.6.x through 4.x before 4.1 allows local users to cause a denial of service or possibly have unspecified other impact via a large iov_count value in a write request.
Impact & exploitability
Attack vectorLocal
Attack complexityLow
Privileges required—
User interaction—
Confidentiality impact—
Integrity impact—
Availability impact—
Exploit probability (EPSS)0%
AV:L/AC:L/Au:N/C:P/I:P/A:P
Affected products we track (1)
Recommendation
Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.
Official patch: http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=451a2886b6bf90e2fb378f7c46c655450fb96e81 ↗
Additional information
- NVD record
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=451a2886b6bf90e2fb378f7c46c655450fb96e81Patch
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=fdc81f45e9f57858da6351836507fbcf1b7583eePatch
- http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00004.htmlAdvisory
- http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00018.htmlAdvisory
- http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00021.htmlAdvisory
- http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00026.htmlAdvisory
- http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00027.htmlAdvisory
- http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00028.htmlAdvisory