Lucene search

K
ubuntucveUbuntu.comUB:CVE-2015-4700
HistoryJun 24, 2015 - 12:00 a.m.

CVE-2015-4700

2015-06-2400:00:00
ubuntu.com
ubuntu.com
13

4.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:N/I:N/A:C

0.0004 Low

EPSS

Percentile

10.1%

The bpf_int_jit_compile function in arch/x86/net/bpf_jit_comp.c in the
Linux kernel before 4.0.6 allows local users to cause a denial of service
(system crash) by creating a packet filter and then loading crafted BPF
instructions that trigger late convergence by the JIT compiler.

Bugs

Notes

Author Note
jdstrand android kernels (flo, goldfish, grouper, maguro, mako and manta) are not supported on the Ubuntu Touch 14.10 and earlier preview kernels linux-lts-saucy no longer receives official support linux-lts-quantal no longer receives official support

4.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:N/I:N/A:C

0.0004 Low

EPSS

Percentile

10.1%