CVE-2015-2041
published 2015-04-21CVE-2015-2041: net/llc/sysctl_net_llc.c in the Linux kernel before 3.19 uses an incorrect data type in a sysctl table, which allows local users to obtain potentially…
PriorityP415medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EPSS
0.47%
38.2th percentile
net/llc/sysctl_net_llc.c in the Linux kernel before 3.19 uses an incorrect data type in a sysctl table, which allows local users to obtain potentially sensitive information from kernel memory or possibly have unspecified other impact by accessing a sysctl entry.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.16.7-ckt9-1 (bookworm) | linux 3.16.7-ckt9-1 (bookworm) |
| linux | linux_kernel | <= 3.18.7 | — |
| linux | linux_kernel | >= 0 < 3.16.7-ckt9-1 | 3.16.7-ckt9-1 |
| linux | linux_kernel | >= 0 < 3.16.7-ckt9-1 | 3.16.7-ckt9-1 |
| linux | linux_kernel | >= 0 < 3.16.7-ckt9-1 | 3.16.7-ckt9-1 |
| linux | linux_kernel | >= 0 < 3.16.7-ckt9-1 | 3.16.7-ckt9-1 |
| linux | linux_kernel | >= 0 < 3.13.0-49.81 | 3.13.0-49.81 |
| suse | suse_linux_enterprise_server | — | — |
CVSS provenance
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv10.0CRITICAL
vendor_ubuntu10.0CRITICAL
vendor_debian4.6MEDIUM
vendor_redhat4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2015-04-09·CVSS 5.0
CVE-2015-1593 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
An integer overflow was discovered in the stack randomization feature of
the Linux kernel on 64 bit platforms. A local attacker could exploit this
flaw to bypass the Address Space Layout Randomization (ASLR) protection
mechanism. (CVE-2015-1593)
An information leak was discovered in the Linux Kernel's handling of
userspace configuration of the link layer control (LLC). A local user could
exploit this flaw to read data from other sysctl settings. (CVE-2015-2041)
An information leak was discovered in how the Linux kernel handles setting
the Reliable Datagram Sockets (RDS) settings. A local user could exploit
this flaw to read data from other sysctl settings. (CVE-2015-2042)
A memory corruption
Ubuntu
Linux kernel (Utopic HWE) vulnerabilities
vendor_ubuntu·2015-04-09·CVSS 5.0
CVE-2015-1593 [MEDIUM] Linux kernel (Utopic HWE) vulnerabilities
Title: Linux kernel (Utopic HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
An integer overflow was discovered in the stack randomization feature of
the Linux kernel on 64 bit platforms. A local attacker could exploit this
flaw to bypass the Address Space Layout Randomization (ASLR) protection
mechanism. (CVE-2015-1593)
An information leak was discovered in the Linux Kernel's handling of
userspace configuration of the link layer control (LLC). A local user could
exploit this flaw to read data from other sysctl settings. (CVE-2015-2041)
An information leak was discovered in how the Linux kernel handles setting
the Reliable Datagram Sockets (RDS) settings. A local user could exploit
this flaw to read data from other sysctl settings. (CVE-2015-2042)
A memo
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2015-04-08·CVSS 6.9
CVE-2014-8159 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that the Linux kernel's Infiniband subsystem did not
properly sanitize its input parameters while registering memory regions
from userspace. A local user could exploit this flaw to cause a denial of
service (system crash) or to potentially gain administrative privileges.
(CVE-2014-8159)
An integer overflow was discovered in the stack randomization feature of
the Linux kernel on 64 bit platforms. A local attacker could exploit this
flaw to bypass the Address Space Layout Randomization (ASLR) protection
mechanism. (CVE-2015-1593)
An information leak was discovered in the Linux Kernel's handling of
userspace configuration of the link layer control (LLC). A local user co
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2015-04-08·CVSS 10.0
CVE-2015-1421 [CRITICAL] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Sun Baoliang discovered a use after free flaw in the Linux kernel's SCTP
(Stream Control Transmission Protocol) subsystem during INIT collisions. A
remote attacker could exploit this flaw to cause a denial of service
(system crash) or potentially escalate their privileges on the system.
(CVE-2015-1421)
Marcelo Leitner discovered a flaw in the Linux kernel's routing of packets
to too many different dsts/too fast. A remote attacker on the same subnet can exploit this
flaw to cause a denial of service (system crash). (CVE-2015-1465)
An integer overflow was discovered in the stack randomization feature of
the Linux kernel on 64 bit platforms. A local attacker could exploit this
flaw to bypass the
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2015-04-08·CVSS 10.0
CVE-2015-1421 [CRITICAL] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Sun Baoliang discovered a use after free flaw in the Linux kernel's SCTP
(Stream Control Transmission Protocol) subsystem during INIT collisions. A
remote attacker could exploit this flaw to cause a denial of service
(system crash) or potentially escalate their privileges on the system.
(CVE-2015-1421)
Marcelo Leitner discovered a flaw in the Linux kernel's routing of packets
to too many different dsts/too fast. A remote attacker on the same subnet can exploit this
flaw to cause a denial of service (system crash). (CVE-2015-1465)
An integer overflow was discovered in the stack randomization feature of
the Linux kernel on 64 bit platforms. A local attacker could exploit this
flaw
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2015-04-08·CVSS 5.0
CVE-2015-1593 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
An integer overflow was discovered in the stack randomization feature of
the Linux kernel on 64 bit platforms. A local attacker could exploit this
flaw to bypass the Address Space Layout Randomization (ASLR) protection
mechanism. (CVE-2015-1593)
An information leak was discovered in the Linux Kernel's handling of
userspace configuration of the link layer control (LLC). A local user could
exploit this flaw to read data from other sysctl settings. (CVE-2015-2041)
An information leak was discovered in how the Linux kernel handles setting
the Reliable Datagram Sockets (RDS) settings. A local user could exploit
this flaw to read data from other sysctl settings. (CVE-2015-2042)
Instructions: After
Red Hat
kernel: llc: information leak in llc2_timeout_table
vendor_redhat·2015-02-20·CVSS 4.6
CVE-2015-2041 [MEDIUM] kernel: llc: information leak in llc2_timeout_table
kernel: llc: information leak in llc2_timeout_table
net/llc/sysctl_net_llc.c in the Linux kernel before 3.19 uses an incorrect data type in a sysctl table, which allows local users to obtain potentially sensitive information from kernel memory or possibly have unspecified other impact by accessing a sysctl entry.
Statement: This issue does not affect the versions of the kernel as shipped with Red Hat Enterprise Linux 5, 6 and 7, MRG and realtime kernels.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: realtime-kernel (Red Hat Enterprise MRG 2) - Not affected
Debian
CVE-2015-2041: linux - net/llc/sysctl_net_llc.c in the Linux kernel before 3.19 uses an incorrect data ...
vendor_debian·2015·CVSS 4.6
CVE-2015-2041 [MEDIUM] CVE-2015-2041: linux - net/llc/sysctl_net_llc.c in the Linux kernel before 3.19 uses an incorrect data ...
net/llc/sysctl_net_llc.c in the Linux kernel before 3.19 uses an incorrect data type in a sysctl table, which allows local users to obtain potentially sensitive information from kernel memory or possibly have unspecified other impact by accessing a sysctl entry.
Scope: local
bookworm: resolved (fixed in 3.16.7-ckt9-1)
bullseye: resolved (fixed in 3.16.7-ckt9-1)
forky: resolved (fixed in 3.16.7-ckt9-1)
sid: resolved (fixed in 3.16.7-ckt9-1)
trixie: resolved (fixed in 3.16.7-ckt9-1)
GHSA
GHSA-rp6h-cpcg-rw4q: net/llc/sysctl_net_llc
ghsa_unreviewed·2022-05-14
CVE-2015-2041 [MEDIUM] GHSA-rp6h-cpcg-rw4q: net/llc/sysctl_net_llc
net/llc/sysctl_net_llc.c in the Linux kernel before 3.19 uses an incorrect data type in a sysctl table, which allows local users to obtain potentially sensitive information from kernel memory or possibly have unspecified other impact by accessing a sysctl entry.
OSV
CVE-2015-2041: net/llc/sysctl_net_llc
osv·2015-04-21·CVSS 4.6
CVE-2015-2041 [MEDIUM] CVE-2015-2041: net/llc/sysctl_net_llc
net/llc/sysctl_net_llc.c in the Linux kernel before 3.19 uses an incorrect data type in a sysctl table, which allows local users to obtain potentially sensitive information from kernel memory or possibly have unspecified other impact by accessing a sysctl entry.
OSV
linux-lts-utopic vulnerabilities
osv·2015-04-09·CVSS 5.0
CVE-2015-1593 [MEDIUM] linux-lts-utopic vulnerabilities
linux-lts-utopic vulnerabilities
An integer overflow was discovered in the stack randomization feature of
the Linux kernel on 64 bit platforms. A local attacker could exploit this
flaw to bypass the Address Space Layout Randomization (ASLR) protection
mechanism. (CVE-2015-1593)
An information leak was discovered in the Linux Kernel's handling of
userspace configuration of the link layer control (LLC). A local user could
exploit this flaw to read data from other sysctl settings. (CVE-2015-2041)
An information leak was discovered in how the Linux kernel handles setting
the Reliable Datagram Sockets (RDS) settings. A local user could exploit
this flaw to read data from other sysctl settings. (CVE-2015-2042)
A memory corruption flaw was discovered in the Linux kernel's scsi
subsystem. A lo
OSV
linux vulnerabilities
osv·2015-04-08·CVSS 10.0
CVE-2015-1421 [CRITICAL] linux vulnerabilities
linux vulnerabilities
Sun Baoliang discovered a use after free flaw in the Linux kernel's SCTP
(Stream Control Transmission Protocol) subsystem during INIT collisions. A
remote attacker could exploit this flaw to cause a denial of service
(system crash) or potentially escalate their privileges on the system.
(CVE-2015-1421)
Marcelo Leitner discovered a flaw in the Linux kernel's routing of packets
to too many different dsts/too fast. A remote attacker on the same subnet can exploit this
flaw to cause a denial of service (system crash). (CVE-2015-1465)
An integer overflow was discovered in the stack randomization feature of
the Linux kernel on 64 bit platforms. A local attacker could exploit this
flaw to bypass the Address Space Layout Randomization (ASLR) protection
mechanism. (CVE-2015
No detection rules found.
No public exploits indexed.
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=6b8d9117ccb4f81b1244aafa7bc70ef8fa45fc49http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00023.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-08/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00004.htmlhttp://www.debian.org/security/2015/dsa-3237http://www.openwall.com/lists/oss-security/2015/02/20/19http://www.securityfocus.com/bid/72729http://www.ubuntu.com/usn/USN-2560-1http://www.ubuntu.com/usn/USN-2561-1http://www.ubuntu.com/usn/USN-2562-1http://www.ubuntu.com/usn/USN-2563-1http://www.ubuntu.com/usn/USN-2564-1http://www.ubuntu.com/usn/USN-2565-1https://bugzilla.redhat.com/show_bug.cgi?id=1195350https://github.com/torvalds/linux/commit/6b8d9117ccb4f81b1244aafa7bc70ef8fa45fc49http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=6b8d9117ccb4f81b1244aafa7bc70ef8fa45fc49http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00023.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-08/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00004.htmlhttp://www.debian.org/security/2015/dsa-3237http://www.openwall.com/lists/oss-security/2015/02/20/19http://www.securityfocus.com/bid/72729http://www.ubuntu.com/usn/USN-2560-1http://www.ubuntu.com/usn/USN-2561-1http://www.ubuntu.com/usn/USN-2562-1http://www.ubuntu.com/usn/USN-2563-1http://www.ubuntu.com/usn/USN-2564-1http://www.ubuntu.com/usn/USN-2565-1https://bugzilla.redhat.com/show_bug.cgi?id=1195350https://github.com/torvalds/linux/commit/6b8d9117ccb4f81b1244aafa7bc70ef8fa45fc49
2015-04-21
Published