Back to search
CVE-2015-2666
Published: May 27, 2015
Modified: Aug 6, 2024
PUBLISHED
Description
Stack-based buffer overflow in the get_matching_model_microcode function in arch/x86/kernel/cpu/microcode/intel_early.c in the Linux kernel before 4.0 allows context-dependent attackers to gain privileges by constructing a crafted microcode header and leveraging root privileges for write access to the initrd.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
FEDORA-2015-4457
vendor-advisory
x_refsource_FEDORA
1032414
vdb-entry
x_refsource_SECTRACK
[oss-security] 20150320 Re: CVE Request: Linux kernel execution in the early microcode loader.
mailing-list
x_refsource_MLIST
RHSA-2015:1534
vendor-advisory
x_refsource_REDHAT
https://bugzilla.redhat.com/show_bug.cgi?id=1204722
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now