MEDIUM · 5.5

CVE-2015-8845

The tm_reclaim_thread function in arch/powerpc/kernel/process.c in the Linux kernel before 4.4.1 on powerpc platforms does not ensure that TM suspend mode exists before proceeding with a tm_reclaim ca...

Vulnerability Description

The tm_reclaim_thread function in arch/powerpc/kernel/process.c in the Linux kernel before 4.4.1 on powerpc platforms does not ensure that TM suspend mode exists before proceeding with a tm_reclaim call, which allows local users to cause a denial of service (TM Bad Thing exception and panic) via a crafted application.

CVSS Score

5.5

MEDIUM

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
LinuxLinux Kernel<= 4.4
SuseSuse Linux Enterprise Live Patching12.0
SuseSuse Linux Enterprise Module For Public Cloud12.0
SuseSuse Linux Enterprise Real Time Extension12
SuseSuse Linux Enterprise Software Development Kit12.0
SuseSuse Linux Enterprise Workstation Extension12.0
NovellSuse Linux Enterprise Desktop12.0
NovellSuse Linux Enterprise Server12.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-8845?

CVE-2015-8845 is a vulnerability with a CVSS score of 5.5 (MEDIUM). The tm_reclaim_thread function in arch/powerpc/kernel/process.c in the Linux kernel before 4.4.1 on powerpc platforms does not ensure that TM suspend mode exists before proceeding with a tm_reclaim ca...

How severe is CVE-2015-8845?

CVE-2015-8845 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-8845?

Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Suse Suse Linux Enterprise Live Patching, Suse Suse Linux Enterprise Module For Public Cloud, Suse Suse Linux Enterprise Real Time Extension, Suse Suse Linux Enterprise Software Development Kit.