CVE-2015-8812
Last modified
CVE-2015-8812 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. drivers/infiniband/hw/cxgb3/iwch_cm.c in the Linux kernel before 4.5 does not properly identify error conditions, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via crafted packets.. EPSS estimates a 14.28% chance of exploitation in the next 30 days.
Description
drivers/infiniband/hw/cxgb3/iwch_cm.c in the Linux kernel before 4.5 does not properly identify error conditions, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via crafted packets.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Novell | Suse Linux Enterprise Real Time Extension | 12 | Sp1 |
| Linux | Linux Kernel | < 3.2.78 | — |
| Linux | Linux Kernel | >= 3.3, < 3.10.99 | — |
| Linux | Linux Kernel | >= 3.11, < 3.12.56 | — |
| Linux | Linux Kernel | >= 3.13, < 3.14.63 | — |
| Linux | Linux Kernel | >= 3.15, < 3.16.35 | — |
| Linux | Linux Kernel | >= 3.17, < 3.18.31 | — |
| Linux | Linux Kernel | >= 3.19, < 4.1.22 | — |
| Linux | Linux Kernel | >= 4.2.0, < 4.4.4 | — |
| Canonical | Ubuntu Linux | 12.04 | — |
| Canonical | Ubuntu Linux | 14.04 | — |
| Canonical | Ubuntu Linux | 15.10 | — |
References
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00094.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00015.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00019.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00025.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00026.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00027.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00028.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00029.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00030.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00031.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00032.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00033.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00034.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00036.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00037.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00045.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-07/msg00005.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00038.htmlMailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-2574.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-2584.htmlThird Party Advisory
- http://www.debian.org/security/2016/dsa-3503Third Party Advisory
- http://www.openwall.com/lists/oss-security/2016/02/11/1Mailing List, Release Notes, Third Party Advisory
- http://www.securityfocus.com/bid/83218Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-2946-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-2946-2Third Party Advisory
- http://www.ubuntu.com/usn/USN-2947-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-2947-2Third Party Advisory
- http://www.ubuntu.com/usn/USN-2947-3Third Party Advisory
- http://www.ubuntu.com/usn/USN-2948-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-2948-2Third Party Advisory
- http://www.ubuntu.com/usn/USN-2949-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-2967-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-2967-2Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1303532Issue Tracking, Third Party Advisory
- https://github.com/torvalds/linux/commit/67f1aee6f45059fd6b0f5b0ecb2c97ad0451f6b3Patch, Vendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00094.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00015.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00019.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00025.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00026.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00027.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00028.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00029.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00030.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00031.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00032.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00033.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00034.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00036.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00037.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00045.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-07/msg00005.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00038.htmlMailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-2574.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-2584.htmlThird Party Advisory
- http://www.debian.org/security/2016/dsa-3503Third Party Advisory
- http://www.openwall.com/lists/oss-security/2016/02/11/1Mailing List, Release Notes, Third Party Advisory
- http://www.securityfocus.com/bid/83218Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-2946-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-2946-2Third Party Advisory
- http://www.ubuntu.com/usn/USN-2947-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-2947-2Third Party Advisory
- http://www.ubuntu.com/usn/USN-2947-3Third Party Advisory
- http://www.ubuntu.com/usn/USN-2948-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-2948-2Third Party Advisory
- http://www.ubuntu.com/usn/USN-2949-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-2967-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-2967-2Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1303532Issue Tracking, Third Party Advisory
- https://github.com/torvalds/linux/commit/67f1aee6f45059fd6b0f5b0ecb2c97ad0451f6b3Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-8812?
How severe is CVE-2015-8812?
How do I fix CVE-2015-8812?
Are you affected by CVE-2015-8812?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
