CVE-2015-5364Infinite Loop in Kernel

CWE-399CWE-835Infinite Loop27 documents10 sources
Severity
7.8HIGHNVD
NVD5.0OSV7.2OSV4.9
EPSS
21.2%
top 4.32%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 31
Latest updateMay 14

Description

The (1) udp_recvmsg and (2) udpv6_recvmsg functions in the Linux kernel before 4.0.6 do not properly consider yielding a processor, which allows remote attackers to cause a denial of service (system hang) via incorrect checksums within a UDP packet flood.

CVSS vector

AV:N/AC:L/C:N/I:N/A:CExploitability: 10.0 | Impact: 6.9

Affected Packages4 packages

NVDlinux/linux_kernel3.33.4.109+8
Debianlinux/linux_kernel< 4.0.7-1+3
Ubuntulinux/linux_kernel< 3.13.0-58.97
Palo Altopaloalto/pan-os

Also affects: Debian Linux 7.0, 8.0, Ubuntu Linux 12.04, 14.04, 15.04, Enterprise Linux 6.5

🔴Vulnerability Details

9
GHSA
GHSA-xx3c-35rv-h773: The (1) udp_recvmsg and (2) udpv6_recvmsg functions in the Linux kernel before 42022-05-14
GHSA
GHSA-2p7j-hg9j-vpj2: The (1) udp_recvmsg and (2) udpv6_recvmsg functions in the Linux kernel before 42022-05-14
OSV
CVE-2015-5366: The (1) udp_recvmsg and (2) udpv6_recvmsg functions in the Linux kernel before 42015-08-31
OSV
CVE-2015-5364: The (1) udp_recvmsg and (2) udpv6_recvmsg functions in the Linux kernel before 42015-08-31
CVEList
CVE-2015-5364: The (1) udp_recvmsg and (2) udpv6_recvmsg functions in the Linux kernel before 42015-08-31

📋Vendor Advisories

14
Palo Alto
PAN-SA-2016-0025 Kernel Vulnerabilities2016-10-04
Android
CVE-2015-5364: Android Security Bulletin 2016-09-01 CVE: CVE-2015-5364 Severity: HIGH References: A-29507402 Upstream kernel2016-09-01
Ubuntu
Linux kernel vulnerabilities2015-08-18
Ubuntu
Linux kernel (OMAP4) vulnerabilities2015-08-18
Ubuntu
Linux kernel vulnerabilities2015-07-24

💬Community

2
Bugzilla
CVE-2015-5364 kernel: net: incorrect processing of checksums in UDP implementation [fedora-all]2015-07-03
Bugzilla
CVE-2015-5366 CVE-2015-5364 kernel: net: incorrect processing of checksums in UDP implementation2015-07-03
CVE-2015-5364 — Infinite Loop in Linux Kernel | cvebase