CVE-2015-5156
published 2015-10-19CVE-2015-5156: The virtnet_probe function in drivers/net/virtio_net.c in the Linux kernel before 4.2 attempts to support a FRAGLIST feature without proper memory allocation…
PriorityP425medium6.1CVSS 2.0
AVAACLAuNCNINAC
EPSS
1.16%
64.2th percentile
The virtnet_probe function in drivers/net/virtio_net.c in the Linux kernel before 4.2 attempts to support a FRAGLIST feature without proper memory allocation, which allows guest OS users to cause a denial of service (buffer overflow and memory corruption) via a crafted sequence of fragmented packets.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.1.5-1 (bookworm) | linux 4.1.5-1 (bookworm) |
| linux | linux_kernel | <= 4.1.10 | — |
| linux | linux_kernel | >= 0 < 4.1.5-1 | 4.1.5-1 |
| linux | linux_kernel | >= 0 < 4.1.5-1 | 4.1.5-1 |
| linux | linux_kernel | >= 0 < 4.1.5-1 | 4.1.5-1 |
| linux | linux_kernel | >= 0 < 4.1.5-1 | 4.1.5-1 |
| linux | linux_kernel | >= 0 < 3.13.0-66.108 | 3.13.0-66.108 |
CVSS provenance
nvdv2.06.1MEDIUMAV:A/AC:L/Au:N/C:N/I:N/A:C
osv6.1MEDIUM
vendor_debian6.1MEDIUM
vendor_redhat6.1MEDIUM
vendor_ubuntu6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (Utopic HWE) vulnerabilities
vendor_ubuntu·2015-10-20·CVSS 6.1
CVE-2015-5156 [MEDIUM] Linux kernel (Utopic HWE) vulnerabilities
Title: Linux kernel (Utopic HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that virtio networking in the Linux kernel did not handle
fragments correctly, leading to kernel memory corruption. A remote attacker
could use this to cause a denial of service (system crash) or possibly
execute code with administrative privileges. (CVE-2015-5156)
Benjamin Randazzo discovered an information leak in the md (multiple
device) driver when the bitmap_info.file is disabled. A local privileged
attacker could use this to obtain sensitive information from the kernel.
(CVE-2015-5697)
Marc-André Lureau discovered that the vhost driver did not properly
release the userspace provided log file descriptor. A privileged attacker
could use this to cause a denia
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2015-10-20·CVSS 5.0
CVE-2015-0272 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that the Linux kernel did not check if a new IPv6 MTU set
by a user space application was valid. A remote attacker could forge a
route advertisement with an invalid MTU that a user space daemon like
NetworkManager would honor and apply to the kernel, causing a denial of
service. (CVE-2015-0272)
It was discovered that virtio networking in the Linux kernel did not handle
fragments correctly, leading to kernel memory corruption. A remote attacker
could use this to cause a denial of service (system crash) or possibly
execute code with administrative privileges. (CVE-2015-5156)
It was discovered that the Reliable Datagram Sockets (RDS) implementation
in the Linux kernel did not v
Ubuntu
Linux kernel (Vivid HWE) vulnerabilities
vendor_ubuntu·2015-10-20·CVSS 5.0
CVE-2015-0272 [MEDIUM] Linux kernel (Vivid HWE) vulnerabilities
Title: Linux kernel (Vivid HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that the Linux kernel did not check if a new IPv6 MTU set
by a user space application was valid. A remote attacker could forge a
route advertisement with an invalid MTU that a user space daemon like
NetworkManager would honor and apply to the kernel, causing a denial of
service. (CVE-2015-0272)
It was discovered that virtio networking in the Linux kernel did not handle
fragments correctly, leading to kernel memory corruption. A remote attacker
could use this to cause a denial of service (system crash) or possibly
execute code with administrative privileges. (CVE-2015-5156)
It was discovered that the Reliable Datagram Sockets (RDS) implementation
in the Linux kern
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2015-10-19·CVSS 6.1
CVE-2015-5156 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that virtio networking in the Linux kernel did not handle
fragments correctly, leading to kernel memory corruption. A remote attacker
could use this to cause a denial of service (system crash) or possibly
execute code with administrative privileges. (CVE-2015-5156)
It was discovered that the Reliable Datagram Sockets (RDS) implementation
in the Linux kernel did not verify sockets were properly bound before
attempting to send a message, which could cause a NULL pointer dereference.
An attacker could use this to cause a denial of service (system crash).
(CVE-2015-6937)
Instructions: After a standard system update you need to reboot your computer to make
all the necessa
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2015-10-19·CVSS 6.1
CVE-2015-5156 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that virtio networking in the Linux kernel did not handle
fragments correctly, leading to kernel memory corruption. A remote attacker
could use this to cause a denial of service (system crash) or possibly
execute code with administrative privileges. (CVE-2015-5156)
It was discovered that the Reliable Datagram Sockets (RDS) implementation
in the Linux kernel did not verify sockets were properly bound before
attempting to send a message, which could cause a NULL pointer dereference.
An attacker could use this to cause a denial of service (system crash).
(CVE-2015-6937)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary chang
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2015-10-19·CVSS 5.0
CVE-2015-0272 [MEDIUM] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that the Linux kernel did not check if a new IPv6 MTU set
by a user space application was valid. A remote attacker could forge a
route advertisement with an invalid MTU that a user space daemon like
NetworkManager would honor and apply to the kernel, causing a denial of
service. (CVE-2015-0272)
It was discovered that virtio networking in the Linux kernel did not handle
fragments correctly, leading to kernel memory corruption. A remote attacker
could use this to cause a denial of service (system crash) or possibly
execute code with administrative privileges. (CVE-2015-5156)
It was discovered that the Reliable Datagram Sockets (RDS) implementation
in the Linux ker
Red Hat
kernel: buffer overflow with fraglist larger than MAX_SKB_FRAGS + 2 in virtio-net
vendor_redhat·2015-08-06·CVSS 6.1
CVE-2015-5156 [MEDIUM] CWE-122 kernel: buffer overflow with fraglist larger than MAX_SKB_FRAGS + 2 in virtio-net
kernel: buffer overflow with fraglist larger than MAX_SKB_FRAGS + 2 in virtio-net
The virtnet_probe function in drivers/net/virtio_net.c in the Linux kernel before 4.2 attempts to support a FRAGLIST feature without proper memory allocation, which allows guest OS users to cause a denial of service (buffer overflow and memory corruption) via a crafted sequence of fragmented packets.
A buffer overflow flaw was found in the way the Linux kernel's virtio-net subsystem handled certain fraglists when the GRO (Generic Receive Offload) functionality was enabled in a bridged network configuration. An attacker on the local network could potentially use this flaw to crash the system, or, although unlikely, elevate their privileges on the system.
Statement: This issue did not affect the Linux kernel
Debian
CVE-2015-5156: linux - The virtnet_probe function in drivers/net/virtio_net.c in the Linux kernel befor...
vendor_debian·2015·CVSS 6.1
CVE-2015-5156 [MEDIUM] CVE-2015-5156: linux - The virtnet_probe function in drivers/net/virtio_net.c in the Linux kernel befor...
The virtnet_probe function in drivers/net/virtio_net.c in the Linux kernel before 4.2 attempts to support a FRAGLIST feature without proper memory allocation, which allows guest OS users to cause a denial of service (buffer overflow and memory corruption) via a crafted sequence of fragmented packets.
Scope: local
bookworm: resolved (fixed in 4.1.5-1)
bullseye: resolved (fixed in 4.1.5-1)
forky: resolved (fixed in 4.1.5-1)
sid: resolved (fixed in 4.1.5-1)
trixie: resolved (fixed in 4.1.5-1)
GHSA
GHSA-hm78-pq45-736h: The virtnet_probe function in drivers/net/virtio_net
ghsa_unreviewed·2022-05-17
CVE-2015-5156 [MEDIUM] CWE-119 GHSA-hm78-pq45-736h: The virtnet_probe function in drivers/net/virtio_net
The virtnet_probe function in drivers/net/virtio_net.c in the Linux kernel before 4.2 attempts to support a FRAGLIST feature without proper memory allocation, which allows guest OS users to cause a denial of service (buffer overflow and memory corruption) via a crafted sequence of fragmented packets.
OSV
linux-lts-utopic vulnerabilities
osv·2015-10-20·CVSS 6.1
CVE-2015-5156 [MEDIUM] linux-lts-utopic vulnerabilities
linux-lts-utopic vulnerabilities
It was discovered that virtio networking in the Linux kernel did not handle
fragments correctly, leading to kernel memory corruption. A remote attacker
could use this to cause a denial of service (system crash) or possibly
execute code with administrative privileges. (CVE-2015-5156)
Benjamin Randazzo discovered an information leak in the md (multiple
device) driver when the bitmap_info.file is disabled. A local privileged
attacker could use this to obtain sensitive information from the kernel.
(CVE-2015-5697)
Marc-André Lureau discovered that the vhost driver did not properly
release the userspace provided log file descriptor. A privileged attacker
could use this to cause a denial of service (resource exhaustion).
(CVE-2015-6252)
It was discovered that
OSV
linux-lts-vivid vulnerabilities
osv·2015-10-20·CVSS 5.0
CVE-2015-0272 [MEDIUM] linux-lts-vivid vulnerabilities
linux-lts-vivid vulnerabilities
It was discovered that the Linux kernel did not check if a new IPv6 MTU set
by a user space application was valid. A remote attacker could forge a
route advertisement with an invalid MTU that a user space daemon like
NetworkManager would honor and apply to the kernel, causing a denial of
service. (CVE-2015-0272)
It was discovered that virtio networking in the Linux kernel did not handle
fragments correctly, leading to kernel memory corruption. A remote attacker
could use this to cause a denial of service (system crash) or possibly
execute code with administrative privileges. (CVE-2015-5156)
It was discovered that the Reliable Datagram Sockets (RDS) implementation
in the Linux kernel did not verify sockets were properly bound before
attempting to send a me
OSV
CVE-2015-5156: The virtnet_probe function in drivers/net/virtio_net
osv·2015-10-19·CVSS 6.1
CVE-2015-5156 [MEDIUM] CVE-2015-5156: The virtnet_probe function in drivers/net/virtio_net
The virtnet_probe function in drivers/net/virtio_net.c in the Linux kernel before 4.2 attempts to support a FRAGLIST feature without proper memory allocation, which allows guest OS users to cause a denial of service (buffer overflow and memory corruption) via a crafted sequence of fragmented packets.
OSV
linux vulnerabilities
osv·2015-10-19·CVSS 5.0
CVE-2015-0272 [MEDIUM] linux vulnerabilities
linux vulnerabilities
It was discovered that the Linux kernel did not check if a new IPv6 MTU set
by a user space application was valid. A remote attacker could forge a
route advertisement with an invalid MTU that a user space daemon like
NetworkManager would honor and apply to the kernel, causing a denial of
service. (CVE-2015-0272)
It was discovered that virtio networking in the Linux kernel did not handle
fragments correctly, leading to kernel memory corruption. A remote attacker
could use this to cause a denial of service (system crash) or possibly
execute code with administrative privileges. (CVE-2015-5156)
It was discovered that the Reliable Datagram Sockets (RDS) implementation
in the Linux kernel did not verify sockets were properly bound before
attempting to send a message, whi
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-5156 kernel: buffer overflow with fraglist larger than MAX_SKB_FRAGS + 2 in virtio-net [fedora-all]
bugzilla·2015-09-25·CVSS 6.1
CVE-2015-5156 [MEDIUM] CVE-2015-5156 kernel: buffer overflow with fraglist larger than MAX_SKB_FRAGS + 2 in virtio-net [fedora-all]
CVE-2015-5156 kernel: buffer overflow with fraglist larger than MAX_SKB_FRAGS + 2 in virtio-net [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects
Bugzilla
CVE-2015-5156 kernel: buffer overflow with fraglist larger than MAX_SKB_FRAGS + 2 in virtio-net
bugzilla·2015-07-16·CVSS 6.1
CVE-2015-5156 [MEDIUM] CVE-2015-5156 kernel: buffer overflow with fraglist larger than MAX_SKB_FRAGS + 2 in virtio-net
CVE-2015-5156 kernel: buffer overflow with fraglist larger than MAX_SKB_FRAGS + 2 in virtio-net
When a guests KVM network devices is in a bridge configuration the kernel can create a situation in which packets are fragmented in an unexpected fashion. The GRO functionality can create a situation in which multiple SKB's are chained together
in a single packets fraglist (by design).
The virtio module declares support for NETIF_F_FRAGLIST and assumes that there are at most MAX_SKB_FRAGS + 2 fragments which isn't always true with a fraglist, when GRO is enabled on the incoming driver it can create more fragments than expected.
A longer than expected fragment list in the socket buffer will make the call to skb_to_sgvec overflow the sg array, leading to memory corruption. It is unlikely that a
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=48900cb6af4282fa0fb6ff4d72a81aa3dadb5c39http://lists.fedoraproject.org/pipermail/package-announce/2015-November/171454.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-October/169378.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-10/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00018.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1978.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0855.htmlhttp://www.debian.org/security/2015/dsa-3364http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/76230http://www.securitytracker.com/id/1034045http://www.ubuntu.com/usn/USN-2773-1http://www.ubuntu.com/usn/USN-2774-1http://www.ubuntu.com/usn/USN-2777-1https://bugzilla.redhat.com/show_bug.cgi?id=1243852https://github.com/torvalds/linux/commit/48900cb6af4282fa0fb6ff4d72a81aa3dadb5c39http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=48900cb6af4282fa0fb6ff4d72a81aa3dadb5c39http://lists.fedoraproject.org/pipermail/package-announce/2015-November/171454.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-October/169378.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-10/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00018.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1978.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0855.htmlhttp://www.debian.org/security/2015/dsa-3364http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/76230http://www.securitytracker.com/id/1034045http://www.ubuntu.com/usn/USN-2773-1http://www.ubuntu.com/usn/USN-2774-1http://www.ubuntu.com/usn/USN-2777-1https://bugzilla.redhat.com/show_bug.cgi?id=1243852https://github.com/torvalds/linux/commit/48900cb6af4282fa0fb6ff4d72a81aa3dadb5c39
2015-10-19
Published