cbcvebase.
CVE-2015-1465
published 2015-04-05

CVE-2015-1465: The IPv4 implementation in the Linux kernel before 3.18.8 does not properly consider the length of the Read-Copy Update (RCU) grace period for redirecting…

PriorityP339high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
6.47%
93.0th percentile
The IPv4 implementation in the Linux kernel before 3.18.8 does not properly consider the length of the Read-Copy Update (RCU) grace period for redirecting lookups in the absence of caching, which allows remote attackers to cause a denial of service (memory consumption or system crash) via a flood of packets.

Affected

15 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debianlinux< linux 3.16.7-ckt7-1 (bookworm)linux 3.16.7-ckt7-1 (bookworm)
googleandroid
linuxlinux_kernel>= 0 < 3.16.7-ckt7-13.16.7-ckt7-1
linuxlinux_kernel>= 0 < 3.16.7-ckt7-13.16.7-ckt7-1
linuxlinux_kernel>= 0 < 3.16.7-ckt7-13.16.7-ckt7-1
linuxlinux_kernel>= 0 < 3.16.7-ckt7-13.16.7-ckt7-1
linuxlinux_kernel>= 0 < 3.13.0-49.813.13.0-49.81
linuxlinux_kernel>= 3.10.50 < 3.10.703.10.70
linuxlinux_kernel>= 3.12.26 < 3.12.383.12.38
linuxlinux_kernel>= 3.14.14 < 3.14.343.14.34
linuxlinux_kernel>= 3.15.7 < 3.16.353.16.35
linuxlinux_kernel>= 3.17 < 3.18.83.18.8

CVSS provenance

nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv10.0CRITICAL
vendor_ubuntu10.0CRITICAL
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.