First published: Wed Jul 01 2015(Updated: )
A flaw was found in the way the Linux kernel's networking implementation handled UDP packets with incorrect checksum values. A remote attacker could potentially use this flaw to trigger an infinite loop in the kernel, resulting in a denial of service on the system, or cause a denial of service in applications using the edge triggered epoll functionality.
Credit: security@debian.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/kernel | <0:2.6.18-408.el5 | 0:2.6.18-408.el5 |
redhat/kernel | <0:2.6.32-573.3.1.el6 | 0:2.6.32-573.3.1.el6 |
redhat/kernel | <0:2.6.32-358.71.1.el6 | 0:2.6.32-358.71.1.el6 |
redhat/kernel | <0:2.6.32-431.72.1.el6 | 0:2.6.32-431.72.1.el6 |
redhat/kernel | <0:2.6.32-504.49.1.el6 | 0:2.6.32-504.49.1.el6 |
redhat/kernel-rt | <0:3.10.0-229.14.1.rt56.141.13.el7_1 | 0:3.10.0-229.14.1.rt56.141.13.el7_1 |
redhat/kernel | <0:3.10.0-229.14.1.ael7b | 0:3.10.0-229.14.1.ael7b |
redhat/kernel-rt | <1:3.10.0-229.rt56.161.el6 | 1:3.10.0-229.rt56.161.el6 |
debian/linux | 5.10.223-1 5.10.226-1 6.1.123-1 6.1.128-1 6.12.12-1 6.12.15-1 | |
Linux Kernel | <3.2.70 | |
Linux Kernel | >=3.3<3.4.109 | |
Linux Kernel | >=3.5<3.10.81 | |
Linux Kernel | >=3.11<3.12.44 | |
Linux Kernel | >=3.13<3.14.45 | |
Linux Kernel | >=3.15<3.16.35 | |
Linux Kernel | >=3.17<3.18.17 | |
Linux Kernel | >=3.19<4.0.6 | |
redhat enterprise Linux server aus | =6.5 | |
Debian | =7.0 | |
Debian | =8.0 | |
Ubuntu | =12.04 | |
Ubuntu | =14.04 | |
Ubuntu | =15.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2015-5364 is classified as a high severity vulnerability due to its potential to cause denial of service.
To fix CVE-2015-5364, you should update the Linux kernel to at least version 0:2.6.18-408.el5 or 0:2.6.32-573.3.1.el6 as recommended by your distribution.
CVE-2015-5364 affects multiple versions of the Linux kernel across various distributions including Red Hat and Ubuntu.
Exploitation of CVE-2015-5364 may lead to an infinite loop in the kernel, resulting in system instability and denial of service.
Yes, CVE-2015-5364 can be exploited remotely by sending crafted UDP packets with incorrect checksum values.