CVE-2015-1339
published 2016-04-27CVE-2015-1339: Memory leak in the cuse_channel_release function in fs/fuse/cuse.c in the Linux kernel before 4.4 allows local users to cause a denial of service (memory…
PriorityP419medium6.2CVSS 3.0
AVLACLPRNUINSUCNINAH
EPSS
0.43%
34.5th percentile
Memory leak in the cuse_channel_release function in fs/fuse/cuse.c in the Linux kernel before 4.4 allows local users to cause a denial of service (memory consumption) or possibly have unspecified other impact by opening /dev/cuse many times.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.4.2-1 (bookworm) | linux 4.4.2-1 (bookworm) |
| linux | linux_kernel | <= 4.3.6 | — |
| linux | linux_kernel | >= 0 < 4.4.2-1 | 4.4.2-1 |
| linux | linux_kernel | >= 0 < 4.4.2-1 | 4.4.2-1 |
| linux | linux_kernel | >= 0 < 4.4.2-1 | 4.4.2-1 |
| linux | linux_kernel | >= 0 < 4.4.2-1 | 4.4.2-1 |
| novell | suse_linux_enterprise_debuginfo | — | — |
| novell | suse_linux_enterprise_real_time_extension | — | — |
CVSS provenance
nvdv3.06.2MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv6.2MEDIUM
vendor_redhat6.8MEDIUM
vendor_debian6.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4g77-cm25-7q33: Memory leak in the cuse_channel_release function in fs/fuse/cuse
ghsa_unreviewed·2022-05-17
CVE-2015-1339 [MEDIUM] GHSA-4g77-cm25-7q33: Memory leak in the cuse_channel_release function in fs/fuse/cuse
Memory leak in the cuse_channel_release function in fs/fuse/cuse.c in the Linux kernel before 4.4 allows local users to cause a denial of service (memory consumption) or possibly have unspecified other impact by opening /dev/cuse many times.
OSV
CVE-2015-1339: Memory leak in the cuse_channel_release function in fs/fuse/cuse
osv·2016-04-27·CVSS 6.2
CVE-2015-1339 [MEDIUM] CVE-2015-1339: Memory leak in the cuse_channel_release function in fs/fuse/cuse
Memory leak in the cuse_channel_release function in fs/fuse/cuse.c in the Linux kernel before 4.4 allows local users to cause a denial of service (memory consumption) or possibly have unspecified other impact by opening /dev/cuse many times.
Red Hat
kernel: Memory exhaustion via CUSE driver
vendor_redhat·2016-03-02·CVSS 6.2
CVE-2015-1339 [MEDIUM] CWE-400 kernel: Memory exhaustion via CUSE driver
kernel: Memory exhaustion via CUSE driver
Memory leak in the cuse_channel_release function in fs/fuse/cuse.c in the Linux kernel before 4.4 allows local users to cause a denial of service (memory consumption) or possibly have unspecified other impact by opening /dev/cuse many times.
Statement: This issue does not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 5, 6, 7 and MRG-2 as the code with the flaw is not present in the products listed.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: realtime-kernel (Red Hat Enterprise MRG 2) - Not affected
Red Hat
webkitgtk: arbitrary code execution and denial of service via a crafted web site (WSA-2015-0001)
vendor_redhat·2015-01-26·CVSS 6.8
CVE-2014-1339 [MEDIUM] webkitgtk: arbitrary code execution and denial of service via a crafted web site (WSA-2015-0001)
webkitgtk: arbitrary code execution and denial of service via a crafted web site (WSA-2015-0001)
WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-05-21-1.
Statement: Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: webkitgtk (Red Hat Enterprise Linux 6) - Will not fix
Package: webkitgtk3 (Red Hat Enterprise Linux
Debian
CVE-2015-1339: linux - Memory leak in the cuse_channel_release function in fs/fuse/cuse.c in the Linux ...
vendor_debian·2015·CVSS 6.2
CVE-2015-1339 [MEDIUM] CVE-2015-1339: linux - Memory leak in the cuse_channel_release function in fs/fuse/cuse.c in the Linux ...
Memory leak in the cuse_channel_release function in fs/fuse/cuse.c in the Linux kernel before 4.4 allows local users to cause a denial of service (memory consumption) or possibly have unspecified other impact by opening /dev/cuse many times.
Scope: local
bookworm: resolved (fixed in 4.4.2-1)
bullseye: resolved (fixed in 4.4.2-1)
forky: resolved (fixed in 4.4.2-1)
sid: resolved (fixed in 4.4.2-1)
trixie: resolved (fixed in 4.4.2-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-1339 kernel: Memory exhaustion via CUSE driver [fedora-all]
bugzilla·2016-03-03·CVSS 6.2
CVE-2015-1339 [MEDIUM] CVE-2015-1339 kernel: Memory exhaustion via CUSE driver [fedora-all]
CVE-2015-1339 kernel: Memory exhaustion via CUSE driver [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. W
Bugzilla
CVE-2015-1339 kernel: Memory exhaustion via CUSE driver
bugzilla·2016-03-03·CVSS 6.2
CVE-2015-1339 [MEDIUM] CVE-2015-1339 kernel: Memory exhaustion via CUSE driver
CVE-2015-1339 kernel: Memory exhaustion via CUSE driver
Kernel memory leak in the CUSE driver using stress-ng was found. It is possible for privileged attacker to cause a local DoS via memory exhaustion by repeatedly opening /dev/cuse for reading.
Upstream patch:
https://git.kernel.org/linus/2c5816b4beccc8ba709144539f6fdd764f8fa49c
References:
https://bugzilla.novell.com/show_bug.cgi?id=969356
http://seclists.org/oss-sec/2016/q1/495
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1314332]
---
Statement:
This issue does not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 5, 6, 7 and MRG-2 as the code with the flaw is not present in the products listed.
Bugzilla
CVE-2014-1339 webkitgtk: arbitrary code execution and denial of service via a crafted web site (WSA-2015-0001)
bugzilla·2015-01-27·CVSS 6.8
CVE-2014-1339 [MEDIUM] CVE-2014-1339 webkitgtk: arbitrary code execution and denial of service via a crafted web site (WSA-2015-0001)
CVE-2014-1339 webkitgtk: arbitrary code execution and denial of service via a crafted web site (WSA-2015-0001)
Following vulnerability was discovered on the 2.4 stable series of WebKitGTK+:
CVE-2014-1339
WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-05-21-1.
External References:
http://webkitgtk.org/security/WSA-2015-0001.html
Discussion:
Statement:
Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Se
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=2c5816b4beccc8ba709144539f6fdd764f8fa49chttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00059.htmlhttp://www.openwall.com/lists/oss-security/2016/03/02/13https://bugzilla.novell.com/show_bug.cgi?id=969356https://bugzilla.redhat.com/show_bug.cgi?id=1314331https://github.com/torvalds/linux/commit/2c5816b4beccc8ba709144539f6fdd764f8fa49chttps://security-tracker.debian.org/tracker/CVE-2015-1339http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=2c5816b4beccc8ba709144539f6fdd764f8fa49chttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00059.htmlhttp://www.openwall.com/lists/oss-security/2016/03/02/13https://bugzilla.novell.com/show_bug.cgi?id=969356https://bugzilla.redhat.com/show_bug.cgi?id=1314331https://github.com/torvalds/linux/commit/2c5816b4beccc8ba709144539f6fdd764f8fa49chttps://security-tracker.debian.org/tracker/CVE-2015-1339
2016-04-27
Published