Lucene search

K
cve[email protected]CVE-2015-7312
HistoryNov 16, 2015 - 11:59 a.m.

CVE-2015-7312

2015-11-1611:59:09
CWE-416
CWE-362
web.nvd.nist.gov
54
cve-2015-7312
advanced union filesystem
aufs
linux kernel
race conditions
denial of service
privilege escalation
madvise
msync
nvd

4.4 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

5.8 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.2%

Multiple race conditions in the Advanced Union Filesystem (aufs) aufs3-mmap.patch and aufs4-mmap.patch patches for the Linux kernel 3.x and 4.x allow local users to cause a denial of service (use-after-free and BUG) or possibly gain privileges via a (1) madvise or (2) msync system call, related to mm/madvise.c and mm/msync.c.

Affected configurations

NVD
Node
linuxlinux_kernelRange3.0.03.19.8
OR
linuxlinux_kernelRange4.0.04.20.15
Node
canonicalubuntu_linuxMatch14.04esm
OR
debiandebian_linuxMatch8.0

4.4 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

5.8 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.2%