Back to search
CVE-2015-8543
Published: Dec 28, 2015
Modified: Aug 6, 2024
PUBLISHED
Description
The networking implementation in the Linux kernel through 4.3.3, as used in Android and other products, does not validate protocol identifiers for certain protocol families, which allows local users to cause a denial of service (NULL function pointer dereference and system crash) or possibly gain privileges by leveraging CLONE_NEWUSER support to execute a crafted SOCK_RAW application.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
RHSA-2016:0855
vendor-advisory
x_refsource_REDHAT
1034892
vdb-entry
x_refsource_SECTRACK
USN-2886-1
vendor-advisory
x_refsource_UBUNTU
USN-2890-3
vendor-advisory
x_refsource_UBUNTU
RHSA-2016:2584
vendor-advisory
x_refsource_REDHAT
RHSA-2016:2574
vendor-advisory
x_refsource_REDHAT
SUSE-SU-2016:1102
vendor-advisory
x_refsource_SUSE
79698
vdb-entry
x_refsource_BID
SUSE-SU-2016:2074
vendor-advisory
x_refsource_SUSE
USN-2890-2
vendor-advisory
x_refsource_UBUNTU
DSA-3426
vendor-advisory
x_refsource_DEBIAN
[oss-security] 20151209 Re: CVE request - Android kernel - IPv6 connect cause a denial of service
mailing-list
x_refsource_MLIST
USN-2890-1
vendor-advisory
x_refsource_UBUNTU
https://bugzilla.redhat.com/show_bug.cgi?id=1290475
x_refsource_CONFIRM
DSA-3434
vendor-advisory
x_refsource_DEBIAN
USN-2888-1
vendor-advisory
x_refsource_UBUNTU
SUSE-SU-2016:0911
vendor-advisory
x_refsource_SUSE
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now