CVE-2015-3288
Description
De CVE.org
mm/memory.c in the Linux kernel before 4.1.4 mishandles anonymous pages, which allows local users to gain privileges or cause a denial of service (page tainting) via a crafted application that triggers writing to page zero.
Déclaration
This issue affects the Linux kernel packages as shipped with Red Hat Enterprise Linux 5. This has been rated as having Low security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.
This issue affects the Linux kernel packages as shipped with Red Hat Enterprise Linux 6, 7 and MRG-2. Future Linux kernel updates for the respective releases might address this issue.
Détails du score du système commun d'évaluation des vulnérabilités (CVSS)
Info alert:Important note
CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).
Répartition des scores CVSS v2
| Red Hat | NVD | cve.org | |
|---|---|---|---|
| Score de base | 7.2 | 7.2 | N/A |
| Vecteur d'attaque | Local | Local | N/A |
| Complexité d'accès | Low | Low | N/A |
| Authentification | None | None | N/A |
| Impact sur la confidentialité | Complete | Complete | N/A |
| Impact sur l'intégrité | Complete | Complete | N/A |
| Impact sur la disponibilité | Complete | Complete | N/A |
Vecteur
Red Hat: AV:L/AC:L/Au:N/C:C/I:C/A:C
NVD: AV:L/AC:L/Au:N/C:C/I:C/A:C
Comprendre la Défaillance (CWE)
Integrity,Other
Technical Impact: Varies by Context; Unexpected State; Alter Execution Logic
Remerciements
Red Hat would like to thank Kirill A. Shutemov (Intel) for reporting this issue.
Questions fréquemment posées
Not sure what something means? Check out our Security Glossary.
Vous souhaitez recevoir des notifications d'errata ? Signez ici.