CVE-2015-2686: High severity linux kernel vulnerability
Following commit fixes a potential kernel arbitrary memory read/write:
http://git.kernel.org/cgit/linux/kernel/git/davem/net.git/commit/?id=4de930efc23b92ddf88ce91c405ee645fe6e27ea
CVE was assigned to this here: http://seclists.org/oss-sec/2015/q1/977
Other sources
net/socket.c in the Linux kernel 3.19 before 3.19.3 does not validate certain range data for (1) sendto and (2) recvfrom system calls, which allows local users to gain privileges by leveraging a subsystem that uses the copyfromiter function in the ioviter interface, as demonstrated by the Bluetooth subsystem.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2686?
CVE-2015-2686 is considered to have a high severity due to its potential for arbitrary memory read and write operations in the Linux kernel.
How do I fix CVE-2015-2686?
To fix CVE-2015-2686, you should update your Linux kernel to version 3.19.3 or later.
What are the affected versions by CVE-2015-2686?
CVE-2015-2686 affects Linux kernel versions 3.19, 3.19.1, and 3.19.2.
What types of systems are vulnerable to CVE-2015-2686?
Systems running vulnerable versions of the Linux kernel, specifically 3.19.x series, are at risk due to CVE-2015-2686.
Are there any workarounds for CVE-2015-2686?
There are no known effective workarounds for CVE-2015-2686; upgrading the kernel is the recommended approach.