CVE-2015-4692
published 2015-07-27CVE-2015-4692: The kvm_apic_has_events function in arch/x86/kvm/lapic.h in the Linux kernel through 4.1.3 allows local users to cause a denial of service (NULL pointer…
PriorityP416medium4.9CVSS 2.0
AVLACLAuNCNINAC
EPSS
0.45%
37.3th percentile
The kvm_apic_has_events function in arch/x86/kvm/lapic.h in the Linux kernel through 4.1.3 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by leveraging /dev/kvm access for an ioctl call.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.0.8-1 (bookworm) | linux 4.0.8-1 (bookworm) |
| linux | linux_kernel | <= 4.1.3 | — |
| linux | linux_kernel | >= 0 < 4.0.8-1 | 4.0.8-1 |
| linux | linux_kernel | >= 0 < 4.0.8-1 | 4.0.8-1 |
| linux | linux_kernel | >= 0 < 4.0.8-1 | 4.0.8-1 |
| linux | linux_kernel | >= 0 < 4.0.8-1 | 4.0.8-1 |
| linux | linux_kernel | >= 0 < 3.13.0-58.97 | 3.13.0-58.97 |
CVSS provenance
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv7.2HIGH
vendor_ubuntu7.2HIGH
vendor_debian4.9MEDIUM
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2015-07-24·CVSS 4.9
CVE-2015-4692 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was discovered in the kvm (kernel virtual machine) subsystem's
kvm_apic_has_events function. A unprivileged local user could exploit this
flaw to cause a denial of service (system crash). (CVE-2015-4692)
A flaw was discovered in how the Linux kernel handles invalid UDP
checksums. A remote attacker could exploit this flaw to cause a denial of
service using a flood of UDP packets with invalid checksums.
(CVE-2015-5364)
A flaw was discovered in how the Linux kernel handles invalid UDP
checksums. A remote attacker can cause a denial of service against
applications that use epoll by injecting a single packet with an invalid
checksum. (CVE-2015-5366)
Instructions: After a standard system up
Ubuntu
Linux kernel (Utopic HWE) vulnerabilities
vendor_ubuntu·2015-07-23·CVSS 4.9
CVE-2015-4692 [MEDIUM] Linux kernel (Utopic HWE) vulnerabilities
Title: Linux kernel (Utopic HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was discovered in the kvm (kernel virtual machine) subsystem's
kvm_apic_has_events function. A unprivileged local user could exploit this
flaw to cause a denial of service (system crash). (CVE-2015-4692)
A flaw was discovered in how the Linux kernel handles invalid UDP
checksums. A remote attacker could exploit this flaw to cause a denial of
service using a flood of UDP packets with invalid checksums.
(CVE-2015-5364)
A flaw was discovered in how the Linux kernel handles invalid UDP
checksums. A remote attacker can cause a denial of service against
applications that use epoll by injecting a single packet with an invalid
checksum. (CVE-2015-5366)
Instructions: After a stand
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2015-07-23·CVSS 7.2
CVE-2015-1805 [HIGH] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was discovered in the user space memory copying for the pipe iovecs
in the Linux kernel. An unprivileged local user could exploit this flaw to
cause a denial of service (system crash) or potentially escalate their
privileges. (CVE-2015-1805)
A flaw was discovered in the kvm (kernel virtual machine) subsystem's
kvm_apic_has_events function. A unprivileged local user could exploit this
flaw to cause a denial of service (system crash). (CVE-2015-4692)
Daniel Borkmann reported a kernel crash in the Linux kernel's BPF filter
JIT optimization. A local attacker could exploit this flaw to cause a
denial of service (system crash). (CVE-2015-4700)
A flaw was discovered in how the L
Ubuntu
Linux kernel (Vivid HWE) vulnerabilities
vendor_ubuntu·2015-07-23·CVSS 4.9
CVE-2015-4692 [MEDIUM] Linux kernel (Vivid HWE) vulnerabilities
Title: Linux kernel (Vivid HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was discovered in the kvm (kernel virtual machine) subsystem's
kvm_apic_has_events function. A unprivileged local user could exploit this
flaw to cause a denial of service (system crash). (CVE-2015-4692)
Daniel Borkmann reported a kernel crash in the Linux kernel's BPF filter
JIT optimization. A local attacker could exploit this flaw to cause a
denial of service (system crash). (CVE-2015-4700)
A flaw was discovered in how the Linux kernel handles invalid UDP
checksums. A remote attacker could exploit this flaw to cause a denial of
service using a flood of UDP packets with invalid checksums.
(CVE-2015-5364)
A flaw was discovered in how the Linux kernel handles invalid UDP
c
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2015-07-23·CVSS 7.2
CVE-2015-1805 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was discovered in the user space memory copying for the pipe iovecs
in the Linux kernel. An unprivileged local user could exploit this flaw to
cause a denial of service (system crash) or potentially escalate their
privileges. (CVE-2015-1805)
A flaw was discovered in the kvm (kernel virtual machine) subsystem's
kvm_apic_has_events function. A unprivileged local user could exploit this
flaw to cause a denial of service (system crash). (CVE-2015-4692)
Daniel Borkmann reported a kernel crash in the Linux kernel's BPF filter
JIT optimization. A local attacker could exploit this flaw to cause a
denial of service (system crash). (CVE-2015-4700)
A flaw was discovered in how the Linux kernel h
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2015-07-23·CVSS 4.9
CVE-2015-4692 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was discovered in the kvm (kernel virtual machine) subsystem's
kvm_apic_has_events function. A unprivileged local user could exploit this
flaw to cause a denial of service (system crash). (CVE-2015-4692)
Daniel Borkmann reported a kernel crash in the Linux kernel's BPF filter
JIT optimization. A local attacker could exploit this flaw to cause a
denial of service (system crash). (CVE-2015-4700)
A flaw was discovered in how the Linux kernel handles invalid UDP
checksums. A remote attacker could exploit this flaw to cause a denial of
service using a flood of UDP packets with invalid checksums.
(CVE-2015-5364)
A flaw was discovered in how the Linux kernel handles invalid UDP
checksums. A
Red Hat
kernel: kvm x86: NULL pointer dereference in kvm_apic_has_events function
vendor_redhat·2015-06-04·CVSS 4.9
CVE-2015-4692 [MEDIUM] CWE-476 kernel: kvm x86: NULL pointer dereference in kvm_apic_has_events function
kernel: kvm x86: NULL pointer dereference in kvm_apic_has_events function
The kvm_apic_has_events function in arch/x86/kvm/lapic.h in the Linux kernel through 4.1.3 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by leveraging /dev/kvm access for an ioctl call.
A DoS flaw was found for a Linux kernel built for the x86 architecture which had the KVM virtualization support(CONFIG_KVM) enabled. The kernel would be vulnerable to a NULL pointer dereference flaw in Linux kernel's kvm_apic_has_events() function while doing an ioctl. An unprivileged user able to access the "/dev/kvm" device could use this flaw to crash the system kernel.
Statement: This issue does not affect the versions of Linux kernel as shi
Debian
CVE-2015-4692: linux - The kvm_apic_has_events function in arch/x86/kvm/lapic.h in the Linux kernel thr...
vendor_debian·2015·CVSS 4.9
CVE-2015-4692 [MEDIUM] CVE-2015-4692: linux - The kvm_apic_has_events function in arch/x86/kvm/lapic.h in the Linux kernel thr...
The kvm_apic_has_events function in arch/x86/kvm/lapic.h in the Linux kernel through 4.1.3 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by leveraging /dev/kvm access for an ioctl call.
Scope: local
bookworm: resolved (fixed in 4.0.8-1)
bullseye: resolved (fixed in 4.0.8-1)
forky: resolved (fixed in 4.0.8-1)
sid: resolved (fixed in 4.0.8-1)
trixie: resolved (fixed in 4.0.8-1)
GHSA
GHSA-wqc9-vcg5-v949: The kvm_apic_has_events function in arch/x86/kvm/lapic
ghsa_unreviewed·2022-05-17
CVE-2015-4692 [MEDIUM] GHSA-wqc9-vcg5-v949: The kvm_apic_has_events function in arch/x86/kvm/lapic
The kvm_apic_has_events function in arch/x86/kvm/lapic.h in the Linux kernel through 4.1.3 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by leveraging /dev/kvm access for an ioctl call.
OSV
CVE-2015-4692: The kvm_apic_has_events function in arch/x86/kvm/lapic
osv·2015-07-27·CVSS 4.9
CVE-2015-4692 [MEDIUM] CVE-2015-4692: The kvm_apic_has_events function in arch/x86/kvm/lapic
The kvm_apic_has_events function in arch/x86/kvm/lapic.h in the Linux kernel through 4.1.3 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by leveraging /dev/kvm access for an ioctl call.
OSV
linux-lts-utopic vulnerabilities
osv·2015-07-23·CVSS 4.9
CVE-2015-4692 [MEDIUM] linux-lts-utopic vulnerabilities
linux-lts-utopic vulnerabilities
A flaw was discovered in the kvm (kernel virtual machine) subsystem's
kvm_apic_has_events function. A unprivileged local user could exploit this
flaw to cause a denial of service (system crash). (CVE-2015-4692)
A flaw was discovered in how the Linux kernel handles invalid UDP
checksums. A remote attacker could exploit this flaw to cause a denial of
service using a flood of UDP packets with invalid checksums.
(CVE-2015-5364)
A flaw was discovered in how the Linux kernel handles invalid UDP
checksums. A remote attacker can cause a denial of service against
applications that use epoll by injecting a single packet with an invalid
checksum. (CVE-2015-5366)
OSV
linux-lts-vivid vulnerabilities
osv·2015-07-23·CVSS 4.9
CVE-2015-4692 [MEDIUM] linux-lts-vivid vulnerabilities
linux-lts-vivid vulnerabilities
A flaw was discovered in the kvm (kernel virtual machine) subsystem's
kvm_apic_has_events function. A unprivileged local user could exploit this
flaw to cause a denial of service (system crash). (CVE-2015-4692)
Daniel Borkmann reported a kernel crash in the Linux kernel's BPF filter
JIT optimization. A local attacker could exploit this flaw to cause a
denial of service (system crash). (CVE-2015-4700)
A flaw was discovered in how the Linux kernel handles invalid UDP
checksums. A remote attacker could exploit this flaw to cause a denial of
service using a flood of UDP packets with invalid checksums.
(CVE-2015-5364)
A flaw was discovered in how the Linux kernel handles invalid UDP
checksums. A remote attacker can cause a denial of service against
applicatio
OSV
linux vulnerabilities
osv·2015-07-23·CVSS 7.2
CVE-2015-1805 [HIGH] linux vulnerabilities
linux vulnerabilities
A flaw was discovered in the user space memory copying for the pipe iovecs
in the Linux kernel. An unprivileged local user could exploit this flaw to
cause a denial of service (system crash) or potentially escalate their
privileges. (CVE-2015-1805)
A flaw was discovered in the kvm (kernel virtual machine) subsystem's
kvm_apic_has_events function. A unprivileged local user could exploit this
flaw to cause a denial of service (system crash). (CVE-2015-4692)
Daniel Borkmann reported a kernel crash in the Linux kernel's BPF filter
JIT optimization. A local attacker could exploit this flaw to cause a
denial of service (system crash). (CVE-2015-4700)
A flaw was discovered in how the Linux kernel handles invalid UDP
checksums. A remote attacker could exploit this flaw to
No detection rules found.
No public exploits indexed.
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=ce40cd3fc7fa40a6119e5fe6c0f2bc0eb4541009http://lists.fedoraproject.org/pipermail/package-announce/2015-June/160829.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-June/161144.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00049.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-08/msg00011.htmlhttp://www.debian.org/security/2015/dsa-3329http://www.openwall.com/lists/oss-security/2015/06/21/1http://www.securityfocus.com/bid/75142http://www.securitytracker.com/id/1032798http://www.ubuntu.com/usn/USN-2680-1http://www.ubuntu.com/usn/USN-2681-1http://www.ubuntu.com/usn/USN-2682-1http://www.ubuntu.com/usn/USN-2683-1http://www.ubuntu.com/usn/USN-2684-1https://bugzilla.redhat.com/show_bug.cgi?id=1230770https://github.com/torvalds/linux/commit/ce40cd3fc7fa40a6119e5fe6c0f2bc0eb4541009http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=ce40cd3fc7fa40a6119e5fe6c0f2bc0eb4541009http://lists.fedoraproject.org/pipermail/package-announce/2015-June/160829.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-June/161144.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00049.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-08/msg00011.htmlhttp://www.debian.org/security/2015/dsa-3329http://www.openwall.com/lists/oss-security/2015/06/21/1http://www.securityfocus.com/bid/75142http://www.securitytracker.com/id/1032798http://www.ubuntu.com/usn/USN-2680-1http://www.ubuntu.com/usn/USN-2681-1http://www.ubuntu.com/usn/USN-2682-1http://www.ubuntu.com/usn/USN-2683-1http://www.ubuntu.com/usn/USN-2684-1https://bugzilla.redhat.com/show_bug.cgi?id=1230770https://github.com/torvalds/linux/commit/ce40cd3fc7fa40a6119e5fe6c0f2bc0eb4541009
2015-07-27
Published