{"api_version":"1","generated_at":"2026-07-23T08:48:52+00:00","cve":"CVE-2015-8543","urls":{"html":"https://cve.report/CVE-2015-8543","api":"https://cve.report/api/cve/CVE-2015-8543.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2015-8543","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2015-8543"},"summary":{"title":"CVE-2015-8543","description":"The networking implementation in the Linux kernel through 4.3.3, as used in Android and other products, does not validate protocol identifiers for certain protocol families, which allows local users to cause a denial of service (NULL function pointer dereference and system crash) or possibly gain privileges by leveraging CLONE_NEWUSER support to execute a crafted SOCK_RAW application.","state":"PUBLISHED","assigner":"mitre","published_at":"2015-12-28 11:59:06","updated_at":"2026-05-06 22:30:45"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"3.1","source":"nvd@nist.gov","type":"Primary","score":"7","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.9","severity":"","vector":"AV:L/AC:M/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:L/AC:M/Au:N/C:C/I:C/A:C","baseScore":6.9,"accessVector":"LOCAL","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.ubuntu.com/usn/USN-2890-3","name":"http://www.ubuntu.com/usn/USN-2890-3","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"USN-2890-3: Linux kernel (Raspberry Pi 2) vulnerabilities | Ubuntu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.ubuntu.com/usn/USN-2888-1","name":"http://www.ubuntu.com/usn/USN-2888-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"USN-2888-1: Linux kernel (Utopic HWE) vulnerabilities | Ubuntu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/torvalds/linux/commit/79462ad02e861803b3840cc782248c7359451cd9","name":"https://github.com/torvalds/linux/commit/79462ad02e861803b3840cc782248c7359451cd9","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"net: add validation for the socket syscall protocol argument · torvalds/linux@79462ad · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.openwall.com/lists/oss-security/2015/12/09/5","name":"http://www.openwall.com/lists/oss-security/2015/12/09/5","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"oss-security - Re: CVE request - Android kernel - IPv6 connect cause\n a denial of service","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=79462ad02e861803b3840cc782248c7359451cd9","name":"http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=79462ad02e861803b3840cc782248c7359451cd9","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"kernel/git/torvalds/linux.git - Linux kernel source tree","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00038.html","name":"http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00038.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"[security-announce] SUSE-SU-2016:2074-1: important: Security update for","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1290475","name":"https://bugzilla.redhat.com/show_bug.cgi?id=1290475","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Third Party Advisory"],"title":"Bug 1290475 – CVE-2015-8543 kernel: IPv6 connect causes DoS via NULL pointer dereference","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1034892","name":"http://www.securitytracker.com/id/1034892","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Linux Kernel Protocol Identifier Bug Lets Local Users Cause Denial of Service Conditions on the Target System - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.ubuntu.com/usn/USN-2886-1","name":"http://www.ubuntu.com/usn/USN-2886-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"USN-2886-1: Linux kernel vulnerabilities | Ubuntu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.ubuntu.com/usn/USN-2890-2","name":"http://www.ubuntu.com/usn/USN-2890-2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"USN-2890-2: Linux kernel (Wily HWE) vulnerabilities | Ubuntu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://rhn.redhat.com/errata/RHSA-2016-2574.html","name":"http://rhn.redhat.com/errata/RHSA-2016-2574.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00094.html","name":"http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00094.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"[security-announce] SUSE-SU-2016:0911-1: important: Security update for","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/79698","name":"http://www.securityfocus.com/bid/79698","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Google Android Kernel CVE-2015-8543 Null Pointer Deference Local Denial of Service Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://rhn.redhat.com/errata/RHSA-2016-0855.html","name":"http://rhn.redhat.com/errata/RHSA-2016-0855.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.debian.org/security/2015/dsa-3426","name":"http://www.debian.org/security/2015/dsa-3426","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Debian -- Security Information -- DSA-3426-1 linux","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00045.html","name":"http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00045.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"[security-announce] SUSE-SU-2016:1102-1: important: Security update for","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.debian.org/security/2016/dsa-3434","name":"http://www.debian.org/security/2016/dsa-3434","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Debian -- Security Information -- DSA-3434-1 linux","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.ubuntu.com/usn/USN-2890-1","name":"http://www.ubuntu.com/usn/USN-2890-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"USN-2890-1: Linux kernel vulnerabilities | Ubuntu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html","name":"http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Oracle Linux Bulletin - April 2016","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://rhn.redhat.com/errata/RHSA-2016-2584.html","name":"http://rhn.redhat.com/errata/RHSA-2016-2584.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2015-8543","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2015-8543","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2015","cve_id":"8543","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T08:20:43.195Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"RHSA-2016:0855","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2016-0855.html"},{"name":"1034892","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1034892"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html"},{"name":"USN-2886-1","tags":["vendor-advisory","x_refsource_UBUNTU","x_transferred"],"url":"http://www.ubuntu.com/usn/USN-2886-1"},{"name":"USN-2890-3","tags":["vendor-advisory","x_refsource_UBUNTU","x_transferred"],"url":"http://www.ubuntu.com/usn/USN-2890-3"},{"name":"RHSA-2016:2584","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2016-2584.html"},{"name":"RHSA-2016:2574","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2016-2574.html"},{"name":"SUSE-SU-2016:1102","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00045.html"},{"name":"79698","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/79698"},{"name":"SUSE-SU-2016:2074","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00038.html"},{"name":"USN-2890-2","tags":["vendor-advisory","x_refsource_UBUNTU","x_transferred"],"url":"http://www.ubuntu.com/usn/USN-2890-2"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://github.com/torvalds/linux/commit/79462ad02e861803b3840cc782248c7359451cd9"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=79462ad02e861803b3840cc782248c7359451cd9"},{"name":"DSA-3426","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"http://www.debian.org/security/2015/dsa-3426"},{"name":"[oss-security] 20151209 Re: CVE request - Android kernel - IPv6 connect cause a denial of service","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2015/12/09/5"},{"name":"USN-2890-1","tags":["vendor-advisory","x_refsource_UBUNTU","x_transferred"],"url":"http://www.ubuntu.com/usn/USN-2890-1"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1290475"},{"name":"DSA-3434","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"http://www.debian.org/security/2016/dsa-3434"},{"name":"USN-2888-1","tags":["vendor-advisory","x_refsource_UBUNTU","x_transferred"],"url":"http://www.ubuntu.com/usn/USN-2888-1"},{"name":"SUSE-SU-2016:0911","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00094.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2015-12-09T00:00:00.000Z","descriptions":[{"lang":"en","value":"The networking implementation in the Linux kernel through 4.3.3, as used in Android and other products, does not validate protocol identifiers for certain protocol families, which allows local users to cause a denial of service (NULL function pointer dereference and system crash) or possibly gain privileges by leveraging CLONE_NEWUSER support to execute a crafted SOCK_RAW application."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-01-04T19:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"RHSA-2016:0855","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://rhn.redhat.com/errata/RHSA-2016-0855.html"},{"name":"1034892","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1034892"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html"},{"name":"USN-2886-1","tags":["vendor-advisory","x_refsource_UBUNTU"],"url":"http://www.ubuntu.com/usn/USN-2886-1"},{"name":"USN-2890-3","tags":["vendor-advisory","x_refsource_UBUNTU"],"url":"http://www.ubuntu.com/usn/USN-2890-3"},{"name":"RHSA-2016:2584","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://rhn.redhat.com/errata/RHSA-2016-2584.html"},{"name":"RHSA-2016:2574","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://rhn.redhat.com/errata/RHSA-2016-2574.html"},{"name":"SUSE-SU-2016:1102","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00045.html"},{"name":"79698","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/79698"},{"name":"SUSE-SU-2016:2074","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00038.html"},{"name":"USN-2890-2","tags":["vendor-advisory","x_refsource_UBUNTU"],"url":"http://www.ubuntu.com/usn/USN-2890-2"},{"tags":["x_refsource_CONFIRM"],"url":"https://github.com/torvalds/linux/commit/79462ad02e861803b3840cc782248c7359451cd9"},{"tags":["x_refsource_CONFIRM"],"url":"http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=79462ad02e861803b3840cc782248c7359451cd9"},{"name":"DSA-3426","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"http://www.debian.org/security/2015/dsa-3426"},{"name":"[oss-security] 20151209 Re: CVE request - Android kernel - IPv6 connect cause a denial of service","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.openwall.com/lists/oss-security/2015/12/09/5"},{"name":"USN-2890-1","tags":["vendor-advisory","x_refsource_UBUNTU"],"url":"http://www.ubuntu.com/usn/USN-2890-1"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1290475"},{"name":"DSA-3434","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"http://www.debian.org/security/2016/dsa-3434"},{"name":"USN-2888-1","tags":["vendor-advisory","x_refsource_UBUNTU"],"url":"http://www.ubuntu.com/usn/USN-2888-1"},{"name":"SUSE-SU-2016:0911","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00094.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2015-8543","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The networking implementation in the Linux kernel through 4.3.3, as used in Android and other products, does not validate protocol identifiers for certain protocol families, which allows local users to cause a denial of service (NULL function pointer dereference and system crash) or possibly gain privileges by leveraging CLONE_NEWUSER support to execute a crafted SOCK_RAW application."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"RHSA-2016:0855","refsource":"REDHAT","url":"http://rhn.redhat.com/errata/RHSA-2016-0855.html"},{"name":"1034892","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1034892"},{"name":"http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html","refsource":"CONFIRM","url":"http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html"},{"name":"USN-2886-1","refsource":"UBUNTU","url":"http://www.ubuntu.com/usn/USN-2886-1"},{"name":"USN-2890-3","refsource":"UBUNTU","url":"http://www.ubuntu.com/usn/USN-2890-3"},{"name":"RHSA-2016:2584","refsource":"REDHAT","url":"http://rhn.redhat.com/errata/RHSA-2016-2584.html"},{"name":"RHSA-2016:2574","refsource":"REDHAT","url":"http://rhn.redhat.com/errata/RHSA-2016-2574.html"},{"name":"SUSE-SU-2016:1102","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00045.html"},{"name":"79698","refsource":"BID","url":"http://www.securityfocus.com/bid/79698"},{"name":"SUSE-SU-2016:2074","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00038.html"},{"name":"USN-2890-2","refsource":"UBUNTU","url":"http://www.ubuntu.com/usn/USN-2890-2"},{"name":"https://github.com/torvalds/linux/commit/79462ad02e861803b3840cc782248c7359451cd9","refsource":"CONFIRM","url":"https://github.com/torvalds/linux/commit/79462ad02e861803b3840cc782248c7359451cd9"},{"name":"http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=79462ad02e861803b3840cc782248c7359451cd9","refsource":"CONFIRM","url":"http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=79462ad02e861803b3840cc782248c7359451cd9"},{"name":"DSA-3426","refsource":"DEBIAN","url":"http://www.debian.org/security/2015/dsa-3426"},{"name":"[oss-security] 20151209 Re: CVE request - Android kernel - IPv6 connect cause a denial of service","refsource":"MLIST","url":"http://www.openwall.com/lists/oss-security/2015/12/09/5"},{"name":"USN-2890-1","refsource":"UBUNTU","url":"http://www.ubuntu.com/usn/USN-2890-1"},{"name":"https://bugzilla.redhat.com/show_bug.cgi?id=1290475","refsource":"CONFIRM","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1290475"},{"name":"DSA-3434","refsource":"DEBIAN","url":"http://www.debian.org/security/2016/dsa-3434"},{"name":"USN-2888-1","refsource":"UBUNTU","url":"http://www.ubuntu.com/usn/USN-2888-1"},{"name":"SUSE-SU-2016:0911","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00094.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2015-8543","datePublished":"2015-12-28T11:00:00.000Z","dateReserved":"2015-12-11T00:00:00.000Z","dateUpdated":"2024-08-06T08:20:43.195Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2015-12-28 11:59:06","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:M/Au:N/C:C/I:C/A:C","baseScore":6.9,"accessVector":"LOCAL","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"MEDIUM","exploitabilityScore":3.4,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"3.2.75","matchCriteriaId":"447A331C-5777-435D-B7B6-89333DF274DA"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.3","versionEndExcluding":"3.4.111","matchCriteriaId":"BCA33A60-D0CC-4CB7-80EC-23170FAC9A74"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.5","versionEndExcluding":"3.10.95","matchCriteriaId":"E7605378-BB0D-4C8C-A83F-115CE036DBBC"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.11","versionEndExcluding":"3.12.52","matchCriteriaId":"D9F8AED6-5B8B-4402-8A3C-E5349F025298"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.13","versionEndExcluding":"3.14.59","matchCriteriaId":"B8AC651B-877B-40A1-B0FB-E13C039FBBCF"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.15","versionEndExcluding":"3.16.35","matchCriteriaId":"7DC4BA70-B111-4D2E-BC78-6601CED68F08"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.17","versionEndExcluding":"3.18.26","matchCriteriaId":"152B915A-F9A5-4DB5-B0B3-DBF5F092773B"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.19","versionEndExcluding":"4.1.16","matchCriteriaId":"F829E177-AAF1-4509-964D-48DA8AE2C8BC"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.2","versionEndExcluding":"4.3.4","matchCriteriaId":"B6B89F94-302A-4313-8FE5-E3C43BD4271E"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2015","CveId":"8543","Ordinal":"1","Title":"CVE-2015-8543","CVE":"CVE-2015-8543","Year":"2015"},"notes":[{"CveYear":"2015","CveId":"8543","Ordinal":"1","NoteData":"The networking implementation in the Linux kernel through 4.3.3, as used in Android and other products, does not validate protocol identifiers for certain protocol families, which allows local users to cause a denial of service (NULL function pointer dereference and system crash) or possibly gain privileges by leveraging CLONE_NEWUSER support to execute a crafted SOCK_RAW application.","Type":"Description","Title":"CVE-2015-8543"},{"CveYear":"2015","CveId":"8543","Ordinal":"2","NoteData":"2015-12-28","Type":"Other","Title":"Published"},{"CveYear":"2015","CveId":"8543","Ordinal":"3","NoteData":"2018-01-04","Type":"Other","Title":"Modified"}]}}}