cbcvebase.
CVE-2015-1420
published 2015-03-16

CVE-2015-1420: Race condition in the handle_to_path function in fs/fhandle.c in the Linux kernel through 3.19.1 allows local users to bypass intended size restrictions and…

PriorityP47low1.9CVSS 2.0
AVLACMAuNCPINAN
EPSS
0.36%
29.1th percentile
Race condition in the handle_to_path function in fs/fhandle.c in the Linux kernel through 3.19.1 allows local users to bypass intended size restrictions and trigger read operations on additional memory locations by changing the handle_bytes value of a file handle during the execution of this function.

Affected

8 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 3.16.7-ckt7-1 (bookworm)linux 3.16.7-ckt7-1 (bookworm)
linuxlinux_kernel<= 3.18.9
linuxlinux_kernel>= 0 < 3.16.7-ckt7-13.16.7-ckt7-1
linuxlinux_kernel>= 0 < 3.16.7-ckt7-13.16.7-ckt7-1
linuxlinux_kernel>= 0 < 3.16.7-ckt7-13.16.7-ckt7-1
linuxlinux_kernel>= 0 < 3.16.7-ckt7-13.16.7-ckt7-1
linuxlinux_kernel>= 0 < 3.13.0-57.953.13.0-57.95

CVSS provenance

nvdv2.01.9LOWAV:L/AC:M/Au:N/C:P/I:N/A:N
osv6.9MEDIUM
vendor_ubuntu6.9MEDIUM
vendor_debian1.9LOW
vendor_redhat1.9LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.