Lucene search

K
nvd[email protected]NVD:CVE-2015-2830
HistoryMay 27, 2015 - 10:59 a.m.

CVE-2015-2830

2015-05-2710:59:06
CWE-264
web.nvd.nist.gov
2

CVSS2

1.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:M/Au:N/C:N/I:P/A:N

AI Score

4.8

Confidence

High

EPSS

0

Percentile

10.1%

arch/x86/kernel/entry_64.S in the Linux kernel before 3.19.2 does not prevent the TS_COMPAT flag from reaching a user-mode task, which might allow local users to bypass the seccomp or audit protection mechanism via a crafted application that uses the (1) fork or (2) close system call, as demonstrated by an attack against seccomp before 3.16.

Affected configurations

NVD
Node
debiandebian_linuxMatch7.0
OR
debiandebian_linuxMatch8.0
Node
linuxlinux_kernelRange3.19.1
Node
canonicalubuntu_linuxMatch12.04lts

References

CVSS2

1.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:M/Au:N/C:N/I:P/A:N

AI Score

4.8

Confidence

High

EPSS

0

Percentile

10.1%