CVE-2015-4004
Summary
| CVE | CVE-2015-4004 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-06-07 23:59:00 UTC |
| Updated | 2022-12-12 20:21:00 UTC |
| Description | The OZWPAN driver in the Linux kernel through 4.0.5 relies on an untrusted length field during packet parsing, which allows remote attackers to obtain sensitive information from kernel memory or cause a denial of service (out-of-bounds read and system crash) via a crafted packet. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| LKML: "Jason A. Donenfeld": [PATCH 0/4] ozwpan: Four remote packet-of-death vulnerabilities |
MLIST |
lkml.org |
Exploit, Vendor Advisory |
| USN-3000-1: Linux kernel (Utopic HWE) vulnerabilities | Ubuntu |
UBUNTU |
www.ubuntu.com |
|
| USN-2998-1: Linux kernel (Trusty HWE) vulnerabilities | Ubuntu |
UBUNTU |
www.ubuntu.com |
|
| USN-3001-1: Linux kernel (Vivid HWE) vulnerabilities | Ubuntu |
UBUNTU |
www.ubuntu.com |
|
| USN-3004-1: Linux kernel (Raspberry Pi 2) vulnerabilities | Ubuntu |
UBUNTU |
www.ubuntu.com |
|
| USN-3002-1: Linux kernel (Wily HWE) vulnerabilities | Ubuntu |
UBUNTU |
www.ubuntu.com |
|
| oss-security - Re: CVE Request: Linux Kernel Ozwpan Driver - Remote packet-of-death vulnerabilities |
MLIST |
openwall.com |
|
| USN-2989-1: Linux kernel vulnerabilities | Ubuntu |
UBUNTU |
www.ubuntu.com |
|
| USN-3003-1: Linux kernel vulnerabilities | Ubuntu |
UBUNTU |
www.ubuntu.com |
|
| Linux Kernel 'ozwpan' Driver Out Of Bounds Read Multiple Memory Corruption Vulnerabilities |
BID |
www.securityfocus.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 671047 EulerOS Security Update for kernel (EulerOS-SA-2021-2588)