LOW · 3.3

CVE-2015-2922

The ndisc_router_discovery function in net/ipv6/ndisc.c in the Neighbor Discovery (ND) protocol implementation in the IPv6 stack in the Linux kernel before 3.19.6 allows remote attackers to reconfigur...

Vulnerability Description

The ndisc_router_discovery function in net/ipv6/ndisc.c in the Neighbor Discovery (ND) protocol implementation in the IPv6 stack in the Linux kernel before 3.19.6 allows remote attackers to reconfigure a hop-limit setting via a small hop_limit value in a Router Advertisement (RA) message.

CVSS Score

3.3

LOW

AV:A/AC:L/Au:N/C:N/I:N/A:P
Confidentiality
NONE
Integrity
NONE
Availability
PARTIAL

Affected Products

VendorProductVersions
LinuxLinux Kernel<= 3.19.5
FedoraprojectFedora20
OracleLinux5.0
OracleSolaris11.3
RedhatEnterprise Mrg2.5
DebianDebian Linux7.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-2922?

CVE-2015-2922 is a vulnerability with a CVSS score of 3.3 (LOW). The ndisc_router_discovery function in net/ipv6/ndisc.c in the Neighbor Discovery (ND) protocol implementation in the IPv6 stack in the Linux kernel before 3.19.6 allows remote attackers to reconfigur...

How severe is CVE-2015-2922?

CVE-2015-2922 has been rated LOW with a CVSS base score of 3.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-2922?

Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Fedoraproject Fedora, Oracle Linux, Oracle Solaris, Redhat Enterprise Mrg.