Vulnerability Description
drivers/infiniband/hw/cxgb3/iwch_cm.c in the Linux kernel before 4.5 does not properly identify error conditions, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via crafted packets.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Novell | Suse Linux Enterprise Real Time Extension | 12 |
| Linux | Linux Kernel | < 3.2.78 |
| Canonical | Ubuntu Linux | 12.04 |
References
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=67f1aeVendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00094.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00015.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00019.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00025.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00026.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00027.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00028.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00029.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00030.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00031.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00032.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00033.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00034.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00036.htmlMailing ListThird Party Advisory
FAQ
What is CVE-2015-8812?
CVE-2015-8812 is a vulnerability with a CVSS score of 9.8 (CRITICAL). drivers/infiniband/hw/cxgb3/iwch_cm.c in the Linux kernel before 4.5 does not properly identify error conditions, which allows remote attackers to execute arbitrary code or cause a denial of service (...
How severe is CVE-2015-8812?
CVE-2015-8812 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2015-8812?
Check the references section above for vendor advisories and patch information. Affected products include: Novell Suse Linux Enterprise Real Time Extension, Linux Linux Kernel, Canonical Ubuntu Linux.