CVE Database
/

CVE-2015-3331

Back to search

CVE-2015-3331

Published: May 27, 2015

Modified: Aug 6, 2024

PUBLISHED

Description

The __driver_rfc4106_decrypt function in arch/x86/crypto/aesni-intel_glue.c in the Linux kernel before 3.19.3 does not properly determine the memory locations used for encrypted data, which allows context-dependent attackers to cause a denial of service (buffer overflow and system crash) or possibly execute arbitrary code by triggering a crypto API call, as demonstrated by use of a libkcapi test program with an AF_ALG(aead) socket.

VendorProductVersions

n/a

n/a

affected
n/a

References

USN-2631-1
vendor-advisory
x_refsource_UBUNTU
SUSE-SU-2015:1491
vendor-advisory
x_refsource_SUSE
SUSE-SU-2015:1489
vendor-advisory
x_refsource_SUSE
USN-2632-1
vendor-advisory
x_refsource_UBUNTU
SUSE-SU-2015:1488
vendor-advisory
x_refsource_SUSE
DSA-3237
vendor-advisory
x_refsource_DEBIAN
RHSA-2015:1199
vendor-advisory
x_refsource_REDHAT
SUSE-SU-2015:1478
vendor-advisory
x_refsource_SUSE
1032416
vdb-entry
x_refsource_SECTRACK
SUSE-SU-2015:1487
vendor-advisory
x_refsource_SUSE
RHSA-2015:1081
vendor-advisory
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now