cbcvebase.
CVE-2015-4036
published 2015-08-31

CVE-2015-4036: Array index error in the tcm_vhost_make_tpg function in drivers/vhost/scsi.c in the Linux kernel before 4.0 might allow guest OS users to cause a denial of…

PriorityP427high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.59%
44.9th percentile
Array index error in the tcm_vhost_make_tpg function in drivers/vhost/scsi.c in the Linux kernel before 4.0 might allow guest OS users to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted VHOST_SCSI_SET_ENDPOINT ioctl call. NOTE: the affected function was renamed to vhost_scsi_make_tpg before the vulnerability was announced.

Affected

13 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 3.16.7-ckt9-1 (bookworm)linux 3.16.7-ckt9-1 (bookworm)
linuxlinux_kernel< 3.10.903.10.90
linuxlinux_kernel
linuxlinux_kernel>= 0 < 3.16.7-ckt9-13.16.7-ckt9-1
linuxlinux_kernel>= 0 < 3.16.7-ckt9-13.16.7-ckt9-1
linuxlinux_kernel>= 0 < 3.16.7-ckt9-13.16.7-ckt9-1
linuxlinux_kernel>= 0 < 3.16.7-ckt9-13.16.7-ckt9-1
linuxlinux_kernel>= 0 < 3.13.0-54.913.13.0-54.91
linuxlinux_kernel>= 3.11 < 3.12.443.12.44
linuxlinux_kernel>= 3.13 < 3.14.573.14.57
linuxlinux_kernel>= 3.15 < 3.16.353.16.35
linuxlinux_kernel>= 3.17 < 3.18.253.18.25
linuxlinux_kernel>= 3.19 < 4.04.0

CVSS provenance

nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.2HIGH
vendor_debian7.2HIGH
vendor_redhat7.2HIGH
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.