CVE-2015-4036: Buffer Overflow

Published Feb 5, 2015
·
Updated

Array index error in the tcmvhostmaketpg function in drivers/vhost/scsi.c in the Linux kernel before 4.0 might allow guest OS users to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted VHOSTSCSISETENDPOINT ioctl call. NOTE: the affected function was renamed to vhostscsimaketpg before the vulnerability was announced.

Other sources

It was reported that in vhostscsimaketpg() the limit for "tpgt" is UINTMAX but the data type of "tpg->tporttpgt" and that is a u16.

In the context it turns out that in vhostscsisetendpoint(), "tpg->tporttpgt" is used as an offset into the vstpg[] array which has VHOSTSCSIMAXTARGET (256) elements, so anything higher than 255 then is invalid. Attached patch corrects this. In vhostscsisendevt() the values higher than 255 are masked, but now that the limit has changed, the mask is not needed.

Upstream fix: http://www.spinics.net/lists/linux-scsi/msg82650.html

Discussion: http://www.openwall.com/lists/oss-security/2015/05/13/4

Red Hat

Affected Software

15 affected componentsFixes available
Linux Linux kernel>3.6<3.10.90
Linux Linux kernel>=3.11<3.12.44
Linux Linux kernel>=3.13<3.14.57
Linux Linux kernel>=3.15<3.16.35
Linux Linux kernel>=3.17<3.18.25
Linux Linux kernel>=3.19<4.0
Linux Linux kernel=3.6
Linux Linux kernel=3.6-rc2
Linux Linux kernel=3.6-rc3
Linux Linux kernel=3.6-rc4
Linux Linux kernel=3.6-rc5
Linux Linux kernel=3.6-rc6
Linux Linux kernel=3.6-rc7
Linux Linux kernel<=3.18.0
debian/linux
5.10.223-15.10.234-16.1.129-16.1.135-16.12.25-1

Event History

Feb 5, 2015
Data Sourced
via Red Hat·04:44 PM
DescriptionSeverityAffected Software
Aug 31, 2015
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·10:08 PM
Description
Sep 20, 2024
Data Sourced
via Ubuntu·01:09 AM
RemedyDescriptionSeverityAffected Software
Apr 16, 2025
Data Sourced
via Debian·03:24 AM
DescriptionAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2015-4036?

CVE-2015-4036 has a high severity rating due to its potential to cause denial of service and memory corruption.

2

How do I fix CVE-2015-4036?

To fix CVE-2015-4036, upgrade your Linux kernel to version 4.0 or higher.

3

Which versions of the Linux kernel are affected by CVE-2015-4036?

CVE-2015-4036 affects Linux kernel versions prior to 4.0, including several specific versions between 3.6 and 3.19.

4

What impact does CVE-2015-4036 have on systems?

CVE-2015-4036 could allow attackers to cause memory corruption and potentially disrupt system services.

5

Is CVE-2015-4036 a common vulnerability in Linux systems?

Yes, CVE-2015-4036 is considered a significant vulnerability due to its impact on widely used Linux kernel versions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203