CVE-2015-4700
published 2015-08-31CVE-2015-4700: The bpf_int_jit_compile function in arch/x86/net/bpf_jit_comp.c in the Linux kernel before 4.0.6 allows local users to cause a denial of service (system crash)…
PriorityP415medium4.9CVSS 2.0
AVLACLAuNCNINAC
EPSS
0.45%
37.3th percentile
The bpf_int_jit_compile function in arch/x86/net/bpf_jit_comp.c in the Linux kernel before 4.0.6 allows local users to cause a denial of service (system crash) by creating a packet filter and then loading crafted BPF instructions that trigger late convergence by the JIT compiler.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.0.7-1 (bookworm) | linux 4.0.7-1 (bookworm) |
| linux | linux_kernel | <= 4.0.5 | — |
| linux | linux_kernel | >= 0 < 4.0.7-1 | 4.0.7-1 |
| linux | linux_kernel | >= 0 < 4.0.7-1 | 4.0.7-1 |
| linux | linux_kernel | >= 0 < 4.0.7-1 | 4.0.7-1 |
| linux | linux_kernel | >= 0 < 4.0.7-1 | 4.0.7-1 |
| linux | linux_kernel | >= 0 < 3.13.0-58.97 | 3.13.0-58.97 |
CVSS provenance
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv7.2HIGH
vendor_ubuntu7.2HIGH
vendor_debian4.9MEDIUM
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2015-07-23·CVSS 7.2
CVE-2015-1805 [HIGH] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was discovered in the user space memory copying for the pipe iovecs
in the Linux kernel. An unprivileged local user could exploit this flaw to
cause a denial of service (system crash) or potentially escalate their
privileges. (CVE-2015-1805)
A flaw was discovered in the kvm (kernel virtual machine) subsystem's
kvm_apic_has_events function. A unprivileged local user could exploit this
flaw to cause a denial of service (system crash). (CVE-2015-4692)
Daniel Borkmann reported a kernel crash in the Linux kernel's BPF filter
JIT optimization. A local attacker could exploit this flaw to cause a
denial of service (system crash). (CVE-2015-4700)
A flaw was discovered in how the L
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2015-07-23·CVSS 7.2
CVE-2015-1805 [HIGH] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was discovered in the user space memory copying for the pipe iovecs
in the Linux kernel. An unprivileged local user could exploit this flaw to
cause a denial of service (system crash) or potentially escalate their
privileges. (CVE-2015-1805)
Daniel Borkmann reported a kernel crash in the Linux kernel's BPF filter
JIT optimization. A local attacker could exploit this flaw to cause a
denial of service (system crash). (CVE-2015-4700)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
Ubuntu
Linux kernel (Vivid HWE) vulnerabilities
vendor_ubuntu·2015-07-23·CVSS 4.9
CVE-2015-4692 [MEDIUM] Linux kernel (Vivid HWE) vulnerabilities
Title: Linux kernel (Vivid HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was discovered in the kvm (kernel virtual machine) subsystem's
kvm_apic_has_events function. A unprivileged local user could exploit this
flaw to cause a denial of service (system crash). (CVE-2015-4692)
Daniel Borkmann reported a kernel crash in the Linux kernel's BPF filter
JIT optimization. A local attacker could exploit this flaw to cause a
denial of service (system crash). (CVE-2015-4700)
A flaw was discovered in how the Linux kernel handles invalid UDP
checksums. A remote attacker could exploit this flaw to cause a denial of
service using a flood of UDP packets with invalid checksums.
(CVE-2015-5364)
A flaw was discovered in how the Linux kernel handles invalid UDP
c
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2015-07-23·CVSS 7.2
CVE-2015-1805 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was discovered in the user space memory copying for the pipe iovecs
in the Linux kernel. An unprivileged local user could exploit this flaw to
cause a denial of service (system crash) or potentially escalate their
privileges. (CVE-2015-1805)
A flaw was discovered in the kvm (kernel virtual machine) subsystem's
kvm_apic_has_events function. A unprivileged local user could exploit this
flaw to cause a denial of service (system crash). (CVE-2015-4692)
Daniel Borkmann reported a kernel crash in the Linux kernel's BPF filter
JIT optimization. A local attacker could exploit this flaw to cause a
denial of service (system crash). (CVE-2015-4700)
A flaw was discovered in how the Linux kernel h
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2015-07-23·CVSS 7.2
CVE-2015-1805 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was discovered in the user space memory copying for the pipe iovecs
in the Linux kernel. An unprivileged local user could exploit this flaw to
cause a denial of service (system crash) or potentially escalate their
privileges. (CVE-2015-1805)
Daniel Borkmann reported a kernel crash in the Linux kernel's BPF filter
JIT optimization. A local attacker could exploit this flaw to cause a
denial of service (system crash). (CVE-2015-4700)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstal
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2015-07-23·CVSS 4.9
CVE-2015-4692 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was discovered in the kvm (kernel virtual machine) subsystem's
kvm_apic_has_events function. A unprivileged local user could exploit this
flaw to cause a denial of service (system crash). (CVE-2015-4692)
Daniel Borkmann reported a kernel crash in the Linux kernel's BPF filter
JIT optimization. A local attacker could exploit this flaw to cause a
denial of service (system crash). (CVE-2015-4700)
A flaw was discovered in how the Linux kernel handles invalid UDP
checksums. A remote attacker could exploit this flaw to cause a denial of
service using a flood of UDP packets with invalid checksums.
(CVE-2015-5364)
A flaw was discovered in how the Linux kernel handles invalid UDP
checksums. A
Ubuntu
Linux kernel (Utopic HWE) vulnerabilities
vendor_ubuntu·2015-07-07·CVSS 1.9
CVE-2015-1420 [LOW] Linux kernel (Utopic HWE) vulnerabilities
Title: Linux kernel (Utopic HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A race condition was discovered in the Linux kernel's file_handle size
verification. A local user could exploit this flaw to read potentially
sensative memory locations. (CVE-2015-1420)
A underflow error was discovered in the Linux kernel's Ozmo Devices USB
over WiFi host controller driver. A remote attacker could exploit this flaw
to cause a denial of service (system crash) or potentially execute
arbitrary code via a specially crafted packet. (CVE-2015-4001)
A bounds check error was discovered in the Linux kernel's Ozmo Devices USB
over WiFi host controller driver. A remote attacker could exploit this flaw
to cause a denial of service (system crash) or potentially execute
arbitr
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2015-07-07·CVSS 1.9
CVE-2015-1420 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
A race condition was discovered in the Linux kernel's file_handle size
verification. A local user could exploit this flaw to read potentially
sensative memory locations. (CVE-2015-1420)
A underflow error was discovered in the Linux kernel's Ozmo Devices USB
over WiFi host controller driver. A remote attacker could exploit this flaw
to cause a denial of service (system crash) or potentially execute
arbitrary code via a specially crafted packet. (CVE-2015-4001)
A bounds check error was discovered in the Linux kernel's Ozmo Devices USB
over WiFi host controller driver. A remote attacker could exploit this flaw
to cause a denial of service (system crash) or potentially execute
arbitrary code via
Red Hat
kernel: Crafted BPF filters may crash kernel during JIT optimisation
vendor_redhat·2015-06-23·CVSS 4.9
CVE-2015-4700 [MEDIUM] CWE-665 kernel: Crafted BPF filters may crash kernel during JIT optimisation
kernel: Crafted BPF filters may crash kernel during JIT optimisation
The bpf_int_jit_compile function in arch/x86/net/bpf_jit_comp.c in the Linux kernel before 4.0.6 allows local users to cause a denial of service (system crash) by creating a packet filter and then loading crafted BPF instructions that trigger late convergence by the JIT compiler.
A flaw was found in the kernel's implementation of the Berkeley Packet Filter (BPF). A local attacker could craft BPF code to crash the system by creating a situation in which the JIT compiler would fail to correctly optimize the JIT image on the last pass. This would lead to the CPU executing instructions that were not part of the JIT code.
Statement: This issue does not affect the Linux kernels as shipped with Red Hat Enterprise Linux 5 and
Debian
CVE-2015-4700: linux - The bpf_int_jit_compile function in arch/x86/net/bpf_jit_comp.c in the Linux ker...
vendor_debian·2015·CVSS 4.9
CVE-2015-4700 [MEDIUM] CVE-2015-4700: linux - The bpf_int_jit_compile function in arch/x86/net/bpf_jit_comp.c in the Linux ker...
The bpf_int_jit_compile function in arch/x86/net/bpf_jit_comp.c in the Linux kernel before 4.0.6 allows local users to cause a denial of service (system crash) by creating a packet filter and then loading crafted BPF instructions that trigger late convergence by the JIT compiler.
Scope: local
bookworm: resolved (fixed in 4.0.7-1)
bullseye: resolved (fixed in 4.0.7-1)
forky: resolved (fixed in 4.0.7-1)
sid: resolved (fixed in 4.0.7-1)
trixie: resolved (fixed in 4.0.7-1)
GHSA
GHSA-rwf7-qw8f-h66g: The bpf_int_jit_compile function in arch/x86/net/bpf_jit_comp
ghsa_unreviewed·2022-05-14
CVE-2015-4700 [MEDIUM] GHSA-rwf7-qw8f-h66g: The bpf_int_jit_compile function in arch/x86/net/bpf_jit_comp
The bpf_int_jit_compile function in arch/x86/net/bpf_jit_comp.c in the Linux kernel before 4.0.6 allows local users to cause a denial of service (system crash) by creating a packet filter and then loading crafted BPF instructions that trigger late convergence by the JIT compiler.
OSV
CVE-2015-4700: The bpf_int_jit_compile function in arch/x86/net/bpf_jit_comp
osv·2015-08-31·CVSS 4.9
CVE-2015-4700 [MEDIUM] CVE-2015-4700: The bpf_int_jit_compile function in arch/x86/net/bpf_jit_comp
The bpf_int_jit_compile function in arch/x86/net/bpf_jit_comp.c in the Linux kernel before 4.0.6 allows local users to cause a denial of service (system crash) by creating a packet filter and then loading crafted BPF instructions that trigger late convergence by the JIT compiler.
OSV
linux-lts-vivid vulnerabilities
osv·2015-07-23·CVSS 4.9
CVE-2015-4692 [MEDIUM] linux-lts-vivid vulnerabilities
linux-lts-vivid vulnerabilities
A flaw was discovered in the kvm (kernel virtual machine) subsystem's
kvm_apic_has_events function. A unprivileged local user could exploit this
flaw to cause a denial of service (system crash). (CVE-2015-4692)
Daniel Borkmann reported a kernel crash in the Linux kernel's BPF filter
JIT optimization. A local attacker could exploit this flaw to cause a
denial of service (system crash). (CVE-2015-4700)
A flaw was discovered in how the Linux kernel handles invalid UDP
checksums. A remote attacker could exploit this flaw to cause a denial of
service using a flood of UDP packets with invalid checksums.
(CVE-2015-5364)
A flaw was discovered in how the Linux kernel handles invalid UDP
checksums. A remote attacker can cause a denial of service against
applicatio
OSV
linux vulnerabilities
osv·2015-07-23·CVSS 7.2
CVE-2015-1805 [HIGH] linux vulnerabilities
linux vulnerabilities
A flaw was discovered in the user space memory copying for the pipe iovecs
in the Linux kernel. An unprivileged local user could exploit this flaw to
cause a denial of service (system crash) or potentially escalate their
privileges. (CVE-2015-1805)
A flaw was discovered in the kvm (kernel virtual machine) subsystem's
kvm_apic_has_events function. A unprivileged local user could exploit this
flaw to cause a denial of service (system crash). (CVE-2015-4692)
Daniel Borkmann reported a kernel crash in the Linux kernel's BPF filter
JIT optimization. A local attacker could exploit this flaw to cause a
denial of service (system crash). (CVE-2015-4700)
A flaw was discovered in how the Linux kernel handles invalid UDP
checksums. A remote attacker could exploit this flaw to
OSV
linux-lts-utopic vulnerabilities
osv·2015-07-07·CVSS 1.9
CVE-2015-1420 [LOW] linux-lts-utopic vulnerabilities
linux-lts-utopic vulnerabilities
A race condition was discovered in the Linux kernel's file_handle size
verification. A local user could exploit this flaw to read potentially
sensative memory locations. (CVE-2015-1420)
A underflow error was discovered in the Linux kernel's Ozmo Devices USB
over WiFi host controller driver. A remote attacker could exploit this flaw
to cause a denial of service (system crash) or potentially execute
arbitrary code via a specially crafted packet. (CVE-2015-4001)
A bounds check error was discovered in the Linux kernel's Ozmo Devices USB
over WiFi host controller driver. A remote attacker could exploit this flaw
to cause a denial of service (system crash) or potentially execute
arbitrary code via a specially crafted packet. (CVE-2015-4002)
A division by zero
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-4700 kernel: Crafted BPF filters may crash kernel during JIT optimisation [fedora-all]
bugzilla·2015-06-30·CVSS 4.9
CVE-2015-4700 [MEDIUM] CVE-2015-4700 kernel: Crafted BPF filters may crash kernel during JIT optimisation [fedora-all]
CVE-2015-4700 kernel: Crafted BPF filters may crash kernel during JIT optimisation [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supp
Bugzilla
CVE-2015-4700 kernel: Crafted BPF filters may crash kernel during JIT optimisation
bugzilla·2015-06-19·CVSS 4.9
CVE-2015-4700 [MEDIUM] CVE-2015-4700 kernel: Crafted BPF filters may crash kernel during JIT optimisation
CVE-2015-4700 kernel: Crafted BPF filters may crash kernel during JIT optimisation
A flaw was found in the kernels implementation of the Berkly Packet Filter.
Specially crafted BPF code may be able to crash the system by creating a
situation in which the JIT compiler will fail to correctly optimise
the JIT image on the last pass. This would to the CPU executing instructions
that were not part of the JIT code.
Workaround:
This issue does not affect most systems by default. An administrator would need to have enabled the BPF JIT to be affected.
It can be disabled immediately with the command:
# echo 0 > /proc/sys/net/core/bpf_jit_enable
Or it can be disabled for all subsequent boots of the system by setting a value in /etc/sysctl.d/44-bpf-jit-disable
## start file ##
net.core.bpf_jit
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=3f7352bf21f8fd7ba3e2fcef9488756f188e12behttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00023.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-08/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00021.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1778.htmlhttp://www.debian.org/security/2015/dsa-3329http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.0.6http://www.openwall.com/lists/oss-security/2015/06/23/2http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/75356http://www.securitytracker.com/id/1033046http://www.ubuntu.com/usn/USN-2679-1http://www.ubuntu.com/usn/USN-2680-1http://www.ubuntu.com/usn/USN-2681-1http://www.ubuntu.com/usn/USN-2683-1http://www.ubuntu.com/usn/USN-2684-1https://bugzilla.redhat.com/show_bug.cgi?id=1233615https://github.com/torvalds/linux/commit/3f7352bf21f8fd7ba3e2fcef9488756f188e12behttps://support.f5.com/csp/article/K05211147http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=3f7352bf21f8fd7ba3e2fcef9488756f188e12behttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00023.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-08/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00021.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1778.htmlhttp://www.debian.org/security/2015/dsa-3329http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.0.6http://www.openwall.com/lists/oss-security/2015/06/23/2http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/75356http://www.securitytracker.com/id/1033046http://www.ubuntu.com/usn/USN-2679-1http://www.ubuntu.com/usn/USN-2680-1http://www.ubuntu.com/usn/USN-2681-1http://www.ubuntu.com/usn/USN-2683-1http://www.ubuntu.com/usn/USN-2684-1https://bugzilla.redhat.com/show_bug.cgi?id=1233615https://github.com/torvalds/linux/commit/3f7352bf21f8fd7ba3e2fcef9488756f188e12behttps://support.f5.com/csp/article/K05211147
2015-08-31
Published