Lucene search

K
ubuntucveUbuntu.comUB:CVE-2015-3332
HistoryApr 21, 2015 - 12:00 a.m.

CVE-2015-3332

2015-04-2100:00:00
ubuntu.com
ubuntu.com
13

4.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:N/I:N/A:C

0.0004 Low

EPSS

Percentile

5.1%

A certain backport in the TCP Fast Open implementation for the Linux kernel
before 3.18 does not properly maintain a count value, which allow local
users to cause a denial of service (system crash) via the Fast Open
feature, as demonstrated by visiting the
chrome://flags/#enable-tcp-fast-open URL when using certain 3.10.x through
3.16.x kernel builds, including longterm-maintenance releases and ckt (aka
Canonical Kernel Team) builds.

Bugs

Notes

Author Note
jdstrand android kernels (flo, goldfish, grouper, maguro, mako and manta) are not supported on the Ubuntu Touch 14.10 and earlier preview kernels linux-lts-saucy no longer receives official support linux-lts-quantal no longer receives official support
henrix This CVE is specific to stable kernels between 3.10 and 3.16, so Trusty and Utopic are affected. All other series are not.
OSVersionArchitecturePackageVersionFilename
ubuntu14.04noarchlinux< 3.13.0-53.89UNKNOWN
ubuntu14.10noarchlinux< 3.16.0-38.52UNKNOWN
ubuntu12.04noarchlinux-lts-trusty< 3.13.0-53.89~precise1UNKNOWN
ubuntu14.04noarchlinux-lts-utopic< 3.16.0-38.52~14.04.1UNKNOWN

4.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:N/I:N/A:C

0.0004 Low

EPSS

Percentile

5.1%