CVE-2015-3288

Description

De CVE.org

mm/memory.c in the Linux kernel before 4.1.4 mishandles anonymous pages, which allows local users to gain privileges or cause a denial of service (page tainting) via a crafted application that triggers writing to page zero.

Déclaration

This issue affects the Linux kernel packages as shipped with Red Hat Enterprise Linux 5. This has been rated as having Low security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.

This issue affects the Linux kernel packages as shipped with Red Hat Enterprise Linux 6, 7 and MRG-2. Future Linux kernel updates for the respective releases might address this issue.

Détails du score du système commun d'évaluation des vulnérabilités (CVSS)

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

Répartition des scores CVSS v2

Red HatNVDcve.org
Score de base7.27.2N/A
Vecteur d'attaqueLocalLocalN/A
Complexité d'accèsLowLowN/A
AuthentificationNoneNoneN/A
Impact sur la confidentialitéCompleteCompleteN/A
Impact sur l'intégritéCompleteCompleteN/A
Impact sur la disponibilitéCompleteCompleteN/A

Vecteur

Red Hat: AV:L/AC:L/Au:N/C:C/I:C/A:C

NVD: AV:L/AC:L/Au:N/C:C/I:C/A:C

Comprendre la Défaillance (CWE)

Integrity,Other

Technical Impact: Varies by Context; Unexpected State; Alter Execution Logic

Remerciements

Red Hat would like to thank Kirill A. Shutemov (Intel) for reporting this issue.

Questions fréquemment posées

Vous souhaitez recevoir des notifications d'errata ? Signez ici.