CVE-2015-5157Improper Interaction Between Multiple Correctly-Behaving Entities in Kernel

Severity
7.2HIGHNVD
EPSS
0.2%
top 55.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 31
Latest updateJun 11

Description

arch/x86/entry/entry_64.S in the Linux kernel before 4.1.6 on the x86_64 platform mishandles IRET faults in processing NMIs that occurred during userspace execution, which might allow local users to gain privileges by triggering an NMI.

CVSS vector

AV:L/AC:L/C:C/I:C/A:CExploitability: 3.9 | Impact: 10.0

Affected Packages6 packages

Also affects: Enterprise Linux 6.7.z

🔴Vulnerability Details

4
GHSA
GHSA-pxrv-r8wg-9vhw: arch/x86/entry/entry_642022-05-17
CVEList
CVE-2015-5157: arch/x86/entry/entry_642015-08-31
OSV
CVE-2015-5157: arch/x86/entry/entry_642015-08-31
Kernel
x86/ldt: Make modify_ldt synchronous2015-07-30

📋Vendor Advisories

8
Microsoft
CVE-2015-5157: NIST NVD Details: https://nvd2024-06-11
Ubuntu
Linux kernel vulnerabilities2015-07-31
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities2015-07-28
Ubuntu
Linux kernel (Vivid HWE) vulnerabilities2015-07-28
Ubuntu
Linux kernel vulnerabilities2015-07-28

💬Community

1
Bugzilla
CVE-2015-5157 kernel: x86-64: IRET faults during NMIs processing2015-09-03
CVE-2015-5157 — Linux Kernel vulnerability | cvebase