CVE-2015-4036

UnknownEPSS 0.59%

Last modified

CVE-2015-4036 is a vulnerability of currently unknown severity. Array index error in the tcm_vhost_make_tpg function in drivers/vhost/scsi.c in the Linux kernel before 4.0 might allow guest OS users to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted VHOST_SCSI_SET_ENDPOINT ioctl call. NOTE: the affected function was renamed to vhost_scsi_make_tpg before the vulnerability was announced.. EPSS estimates a 0.59% chance of exploitation in the next 30 days.

Description

Array index error in the tcm_vhost_make_tpg function in drivers/vhost/scsi.c in the Linux kernel before 4.0 might allow guest OS users to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted VHOST_SCSI_SET_ENDPOINT ioctl call. NOTE: the affected function was renamed to vhost_scsi_make_tpg before the vulnerability was announced.

Metrics

EPSS Probability
0.59%

43.6th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
LinuxLinux Kernel> 3.6, < 3.10.90
LinuxLinux Kernel>= 3.11, < 3.12.44
LinuxLinux Kernel>= 3.13, < 3.14.57
LinuxLinux Kernel>= 3.15, < 3.16.35
LinuxLinux Kernel>= 3.17, < 3.18.25
LinuxLinux Kernel>= 3.19, < 4.0
LinuxLinux Kernel3.6

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2015-4036?
Array index error in the tcm_vhost_make_tpg function in drivers/vhost/scsi.c in the Linux kernel before 4.0 might allow guest OS users to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted VHOST_SCSI_SET_ENDPOINT ioctl call. NOTE: the affected function was renamed to vhost_scsi_make_tpg before the vulnerability was announced.
How severe is CVE-2015-4036?
Severity scoring for CVE-2015-4036 is pending analysis. The EPSS model estimates a 0.59% probability of exploitation in the next 30 days.
How do I fix CVE-2015-4036?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2015-4036?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST