CVE
- Id
- 80913
- CVE No.
- CVE-2015-3636
- Status
- Candidate
- Description
- The ping_unhash function in net/ipv4/ping.c in the Linux kernel before 4.0.3 does not initialize a certain list data structure during an unhash operation, which allows local users to gain privileges or cause a denial of service (use-after-free and system crash) by leveraging the ability to make a SOCK_DGRAM socket system call for the IPPROTO_ICMP or IPPROTO_ICMPV6 protocol, and then making a connect system call after a disconnect.
- Phase
- Assigned (20150502)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
729842 | 80913 | CVE-2015-3636 | MLIST:[oss-security] 20150502 CVE request for a fixed bug existed in all versions of linux kernel from KeenTeam | View |
729843 | 80913 | CVE-2015-3636 | URL:http://www.openwall.com/lists/oss-security/2015/05/02/5 | View |
729844 | 80913 | CVE-2015-3636 | CONFIRM:http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=a134f083e79fb4c3d0a925691e732c56911b4326 | View |
729845 | 80913 | CVE-2015-3636 | CONFIRM:http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.0.3 | View |
729846 | 80913 | CVE-2015-3636 | CONFIRM:https://bugzilla.redhat.com/show_bug.cgi?id=1218074 | View |
729847 | 80913 | CVE-2015-3636 | CONFIRM:https://github.com/torvalds/linux/commit/a134f083e79fb4c3d0a925691e732c56911b4326 | View |
729848 | 80913 | CVE-2015-3636 | CONFIRM:http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html | View |
729849 | 80913 | CVE-2015-3636 | DEBIAN:DSA-3290 | View |
729850 | 80913 | CVE-2015-3636 | URL:http://www.debian.org/security/2015/dsa-3290 | View |
729851 | 80913 | CVE-2015-3636 | FEDORA:FEDORA-2015-7784 | View |
729852 | 80913 | CVE-2015-3636 | URL:http://lists.fedoraproject.org/pipermail/package-announce/2015-May/157788.html | View |
729853 | 80913 | CVE-2015-3636 | FEDORA:FEDORA-2015-7736 | View |
729854 | 80913 | CVE-2015-3636 | URL:http://lists.fedoraproject.org/pipermail/package-announce/2015-May/157897.html | View |
729855 | 80913 | CVE-2015-3636 | FEDORA:FEDORA-2015-8518 | View |
729856 | 80913 | CVE-2015-3636 | URL:http://lists.fedoraproject.org/pipermail/package-announce/2015-May/158804.html | View |
729857 | 80913 | CVE-2015-3636 | REDHAT:RHSA-2015:1564 | View |
729858 | 80913 | CVE-2015-3636 | URL:http://rhn.redhat.com/errata/RHSA-2015-1564.html | View |
729859 | 80913 | CVE-2015-3636 | REDHAT:RHSA-2015:1583 | View |
729860 | 80913 | CVE-2015-3636 | URL:http://rhn.redhat.com/errata/RHSA-2015-1583.html | View |
729861 | 80913 | CVE-2015-3636 | REDHAT:RHSA-2015:1643 | View |
729862 | 80913 | CVE-2015-3636 | URL:http://rhn.redhat.com/errata/RHSA-2015-1643.html | View |
729863 | 80913 | CVE-2015-3636 | REDHAT:RHSA-2015:1534 | View |
729864 | 80913 | CVE-2015-3636 | URL:http://rhn.redhat.com/errata/RHSA-2015-1534.html | View |
729865 | 80913 | CVE-2015-3636 | SUSE:SUSE-SU-2015:1478 | View |
729866 | 80913 | CVE-2015-3636 | URL:http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00004.html | View |
729867 | 80913 | CVE-2015-3636 | SUSE:SUSE-SU-2015:1224 | View |
729868 | 80913 | CVE-2015-3636 | URL:http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00023.html | View |
729869 | 80913 | CVE-2015-3636 | SUSE:openSUSE-SU-2015:1382 | View |
729870 | 80913 | CVE-2015-3636 | URL:http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00011.html | View |
729871 | 80913 | CVE-2015-3636 | SUSE:SUSE-SU-2015:1487 | View |
729872 | 80913 | CVE-2015-3636 | URL:http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00007.html | View |
729873 | 80913 | CVE-2015-3636 | SUSE:SUSE-SU-2015:1488 | View |
729874 | 80913 | CVE-2015-3636 | URL:http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00008.html | View |
729875 | 80913 | CVE-2015-3636 | SUSE:SUSE-SU-2015:1489 | View |
729876 | 80913 | CVE-2015-3636 | URL:http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00009.html | View |
729877 | 80913 | CVE-2015-3636 | SUSE:SUSE-SU-2015:1491 | View |
729878 | 80913 | CVE-2015-3636 | URL:http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00011.html | View |
729879 | 80913 | CVE-2015-3636 | UBUNTU:USN-2631-1 | View |
729880 | 80913 | CVE-2015-3636 | URL:http://www.ubuntu.com/usn/USN-2631-1 | View |
729881 | 80913 | CVE-2015-3636 | UBUNTU:USN-2632-1 | View |
729882 | 80913 | CVE-2015-3636 | URL:http://www.ubuntu.com/usn/USN-2632-1 | View |
729883 | 80913 | CVE-2015-3636 | UBUNTU:USN-2633-1 | View |
729884 | 80913 | CVE-2015-3636 | URL:http://www.ubuntu.com/usn/USN-2633-1 | View |
729885 | 80913 | CVE-2015-3636 | UBUNTU:USN-2634-1 | View |
729886 | 80913 | CVE-2015-3636 | URL:http://www.ubuntu.com/usn/USN-2634-1 | View |
729887 | 80913 | CVE-2015-3636 | BID:74450 | View |
729888 | 80913 | CVE-2015-3636 | URL:http://www.securityfocus.com/bid/74450 | View |
729889 | 80913 | CVE-2015-3636 | SECTRACK:1033186 | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
8046 | JVNDB-2015-003366 | Apple iOS および Apple OS X の CoreText における任意のコードを実行される脆弱性 | Apple iOS および Apple OS X の CoreText には、任意のコードを実行される、またはサービス運用妨害 (メモリ破損) 状態にされる脆弱性が存在します。 | CVE-2015-3688 | 80913 | 6.8 | http://jvndb.jvn.jp/ja/contents/2015/JVNDB-2015-003366.html | View |