CVE-2015-4004: Buffer Overflow
Last updated 24 July 2024
Other sources
The OZWPAN driver in the Linux kernel through 4.0.5 relies on an untrusted length field during packet parsing, which allows remote attackers to obtain sensitive information from kernel memory or cause a denial of service (out-of-bounds read and system crash) via a crafted packet.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2015-4004?
CVE-2015-4004 is a vulnerability in the OZWPAN driver in the Linux kernel that allows remote attackers to obtain sensitive information from kernel memory or cause a denial of service.
What is the impact of CVE-2015-4004?
The impact of CVE-2015-4004 is that remote attackers can obtain sensitive information from kernel memory or cause a denial of service.
How does CVE-2015-4004 work?
CVE-2015-4004 works by exploiting an untrusted length field in the OZWPAN driver during packet parsing.
What software is affected by CVE-2015-4004?
The Linux kernel versions through 4.0.5 are affected by CVE-2015-4004.
How do I fix CVE-2015-4004?
To fix CVE-2015-4004, update the Linux kernel to version 4.0.6 or later.