CVE-2015-3332: Medium severity debian linux vulnerability
A certain backport in the TCP Fast Open implementation for the Linux kernel before 3.18 does not properly maintain a count value, which allow local users to cause a denial of service (system crash) via the Fast Open feature, as demonstrated by visiting the chrome://flags/#enable-tcp-fast-open URL when using certain 3.10.x through 3.16.x kernel builds, including longterm-maintenance releases and ckt (aka Canonical Kernel Team) builds.
Other sources
Linux kernel built with the IPv4 networking support(CONFIGNET) is vulnerable to a DoS flaw. It could occur while using TCP Fast open option when initiating a network connection. This issue is a regression caused by upstream commit '355a901e6cf1', when it was back-ported to older 3.10.y - 3.16.y branches.
An unprivileged local user could use this flaw to crash the system resulting in DoS.
Upstream fix: ------------- -> http://www.spinics.net/lists/netdev/msg325602.html
References: ----------- -> http://www.openwall.com/lists/oss-security/2015/04/18/2 -> https://bugs.debian.org/782515
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-3332?
CVE-2015-3332 has a severity level that may allow local users to cause a denial of service.
How do I fix CVE-2015-3332?
To fix CVE-2015-3332, upgrade your Linux kernel to version 3.18 or later.
Which Linux distributions are affected by CVE-2015-3332?
CVE-2015-3332 affects Debian GNU/Linux and Linux kernel versions up to 3.17.8.
What is the exploit method for CVE-2015-3332?
The exploit method for CVE-2015-3332 involves local users leveraging the Fast Open feature.
Can CVE-2015-3332 be exploited remotely?
CVE-2015-3332 is not a remote vulnerability and requires local access to exploit.