CVE-2015-5706
published 2015-08-31CVE-2015-5706: Use-after-free vulnerability in the path_openat function in fs/namei.c in the Linux kernel 3.x and 4.x before 4.0.4 allows local users to cause a denial of…
PriorityP416medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EPSS
0.44%
35.3th percentile
Use-after-free vulnerability in the path_openat function in fs/namei.c in the Linux kernel 3.x and 4.x before 4.0.4 allows local users to cause a denial of service or possibly have unspecified other impact via O_TMPFILE filesystem operations that leverage a duplicate cleanup operation.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | linux | < linux 4.0.4-1 (bookworm) | linux 4.0.4-1 (bookworm) |
| android | — | — | |
| linux | linux_kernel | >= 0 < 4.0.4-1 | 4.0.4-1 |
| linux | linux_kernel | >= 0 < 4.0.4-1 | 4.0.4-1 |
| linux | linux_kernel | >= 0 < 4.0.4-1 | 4.0.4-1 |
| linux | linux_kernel | >= 0 < 4.0.4-1 | 4.0.4-1 |
| linux | linux_kernel | >= 0 < 3.13.0-58.97 | 3.13.0-58.97 |
| linux | linux_kernel | 3.0 – 3.19.8 | — |
| linux | linux_kernel | >= 4.0 < 4.0.4 | 4.0.4 |
CVSS provenance
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv7.2HIGH
vendor_ubuntu7.2HIGH
vendor_debian4.6MEDIUM
vendor_redhat4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2g53-3pj8-qvxv: Use-after-free vulnerability in the path_openat function in fs/namei
ghsa_unreviewed·2022-05-13
CVE-2015-5706 [MEDIUM] CWE-416 GHSA-2g53-3pj8-qvxv: Use-after-free vulnerability in the path_openat function in fs/namei
Use-after-free vulnerability in the path_openat function in fs/namei.c in the Linux kernel 3.x and 4.x before 4.0.4 allows local users to cause a denial of service or possibly have unspecified other impact via O_TMPFILE filesystem operations that leverage a duplicate cleanup operation.
OSV
CVE-2015-5706: Use-after-free vulnerability in the path_openat function in fs/namei
osv·2015-08-31·CVSS 4.6
CVE-2015-5706 [MEDIUM] CVE-2015-5706: Use-after-free vulnerability in the path_openat function in fs/namei
Use-after-free vulnerability in the path_openat function in fs/namei.c in the Linux kernel 3.x and 4.x before 4.0.4 allows local users to cause a denial of service or possibly have unspecified other impact via O_TMPFILE filesystem operations that leverage a duplicate cleanup operation.
OSV
linux vulnerabilities
osv·2015-07-23·CVSS 7.2
CVE-2015-1805 [HIGH] linux vulnerabilities
linux vulnerabilities
A flaw was discovered in the user space memory copying for the pipe iovecs
in the Linux kernel. An unprivileged local user could exploit this flaw to
cause a denial of service (system crash) or potentially escalate their
privileges. (CVE-2015-1805)
A flaw was discovered in the kvm (kernel virtual machine) subsystem's
kvm_apic_has_events function. A unprivileged local user could exploit this
flaw to cause a denial of service (system crash). (CVE-2015-4692)
Daniel Borkmann reported a kernel crash in the Linux kernel's BPF filter
JIT optimization. A local attacker could exploit this flaw to cause a
denial of service (system crash). (CVE-2015-4700)
A flaw was discovered in how the Linux kernel handles invalid UDP
checksums. A remote attacker could exploit this flaw to
OSV
linux-lts-vivid vulnerabilities
osv·2015-07-07·CVSS 1.9
CVE-2015-1420 [LOW] linux-lts-vivid vulnerabilities
linux-lts-vivid vulnerabilities
A race condition was discovered in the Linux kernel's file_handle size
verification. A local user could exploit this flaw to read potentially
sensative memory locations. (CVE-2015-1420)
A underflow error was discovered in the Linux kernel's Ozmo Devices USB
over WiFi host controller driver. A remote attacker could exploit this flaw
to cause a denial of service (system crash) or potentially execute
arbitrary code via a specially crafted packet. (CVE-2015-4001)
A bounds check error was discovered in the Linux kernel's Ozmo Devices USB
over WiFi host controller driver. A remote attacker could exploit this flaw
to cause a denial of service (system crash) or potentially execute
arbitrary code via a specially crafted packet. (CVE-2015-4002)
A division by zero
OSV
linux-lts-utopic vulnerabilities
osv·2015-07-07·CVSS 1.9
CVE-2015-1420 [LOW] linux-lts-utopic vulnerabilities
linux-lts-utopic vulnerabilities
A race condition was discovered in the Linux kernel's file_handle size
verification. A local user could exploit this flaw to read potentially
sensative memory locations. (CVE-2015-1420)
A underflow error was discovered in the Linux kernel's Ozmo Devices USB
over WiFi host controller driver. A remote attacker could exploit this flaw
to cause a denial of service (system crash) or potentially execute
arbitrary code via a specially crafted packet. (CVE-2015-4001)
A bounds check error was discovered in the Linux kernel's Ozmo Devices USB
over WiFi host controller driver. A remote attacker could exploit this flaw
to cause a denial of service (system crash) or potentially execute
arbitrary code via a specially crafted packet. (CVE-2015-4002)
A division by zero
Android
CVE-2015-5706: Android Security Bulletin 2017-01-01
CVE: CVE-2015-5706
Severity: CRITICAL
References: A-32289301
Upstream kernel
vendor_android·2017-01-01·CVSS 4.6
CVE-2015-5706 [MEDIUM] CVE-2015-5706: Android Security Bulletin 2017-01-01
CVE: CVE-2015-5706
Severity: CRITICAL
References: A-32289301
Upstream kernel
Android Security Bulletin 2017-01-01
CVE: CVE-2015-5706
Severity: CRITICAL
References: A-32289301
Upstream kernel
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2015-07-23·CVSS 7.2
CVE-2015-1805 [HIGH] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was discovered in the user space memory copying for the pipe iovecs
in the Linux kernel. An unprivileged local user could exploit this flaw to
cause a denial of service (system crash) or potentially escalate their
privileges. (CVE-2015-1805)
A flaw was discovered in the kvm (kernel virtual machine) subsystem's
kvm_apic_has_events function. A unprivileged local user could exploit this
flaw to cause a denial of service (system crash). (CVE-2015-4692)
Daniel Borkmann reported a kernel crash in the Linux kernel's BPF filter
JIT optimization. A local attacker could exploit this flaw to cause a
denial of service (system crash). (CVE-2015-4700)
A flaw was discovered in how the L
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2015-07-23·CVSS 7.2
CVE-2015-1805 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was discovered in the user space memory copying for the pipe iovecs
in the Linux kernel. An unprivileged local user could exploit this flaw to
cause a denial of service (system crash) or potentially escalate their
privileges. (CVE-2015-1805)
A flaw was discovered in the kvm (kernel virtual machine) subsystem's
kvm_apic_has_events function. A unprivileged local user could exploit this
flaw to cause a denial of service (system crash). (CVE-2015-4692)
Daniel Borkmann reported a kernel crash in the Linux kernel's BPF filter
JIT optimization. A local attacker could exploit this flaw to cause a
denial of service (system crash). (CVE-2015-4700)
A flaw was discovered in how the Linux kernel h
Ubuntu
Linux kernel (Utopic HWE) vulnerabilities
vendor_ubuntu·2015-07-07·CVSS 1.9
CVE-2015-1420 [LOW] Linux kernel (Utopic HWE) vulnerabilities
Title: Linux kernel (Utopic HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A race condition was discovered in the Linux kernel's file_handle size
verification. A local user could exploit this flaw to read potentially
sensative memory locations. (CVE-2015-1420)
A underflow error was discovered in the Linux kernel's Ozmo Devices USB
over WiFi host controller driver. A remote attacker could exploit this flaw
to cause a denial of service (system crash) or potentially execute
arbitrary code via a specially crafted packet. (CVE-2015-4001)
A bounds check error was discovered in the Linux kernel's Ozmo Devices USB
over WiFi host controller driver. A remote attacker could exploit this flaw
to cause a denial of service (system crash) or potentially execute
arbitr
Ubuntu
Linux kernel (Vivid HWE) vulnerabilities
vendor_ubuntu·2015-07-07·CVSS 1.9
CVE-2015-1420 [LOW] Linux kernel (Vivid HWE) vulnerabilities
Title: Linux kernel (Vivid HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A race condition was discovered in the Linux kernel's file_handle size
verification. A local user could exploit this flaw to read potentially
sensative memory locations. (CVE-2015-1420)
A underflow error was discovered in the Linux kernel's Ozmo Devices USB
over WiFi host controller driver. A remote attacker could exploit this flaw
to cause a denial of service (system crash) or potentially execute
arbitrary code via a specially crafted packet. (CVE-2015-4001)
A bounds check error was discovered in the Linux kernel's Ozmo Devices USB
over WiFi host controller driver. A remote attacker could exploit this flaw
to cause a denial of service (system crash) or potentially execute
arbitra
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2015-07-07·CVSS 1.9
CVE-2015-1420 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
A race condition was discovered in the Linux kernel's file_handle size
verification. A local user could exploit this flaw to read potentially
sensative memory locations. (CVE-2015-1420)
A underflow error was discovered in the Linux kernel's Ozmo Devices USB
over WiFi host controller driver. A remote attacker could exploit this flaw
to cause a denial of service (system crash) or potentially execute
arbitrary code via a specially crafted packet. (CVE-2015-4001)
A bounds check error was discovered in the Linux kernel's Ozmo Devices USB
over WiFi host controller driver. A remote attacker could exploit this flaw
to cause a denial of service (system crash) or potentially execute
arbitrary code via
Red Hat
kernel: Use-after-free in path lookup
vendor_redhat·2015-05-09·CVSS 4.6
CVE-2015-5706 [MEDIUM] CWE-416 kernel: Use-after-free in path lookup
kernel: Use-after-free in path lookup
Use-after-free vulnerability in the path_openat function in fs/namei.c in the Linux kernel 3.x and 4.x before 4.0.4 allows local users to cause a denial of service or possibly have unspecified other impact via O_TMPFILE filesystem operations that leverage a duplicate cleanup operation.
A use-after-free flaw was found in the Linux kernels function path_openat() in which incorrectly clears up twice (as part of path_lookupat() called by do_tmpfile()). Clearing twice can lead to a double fput(). A local, unauthenticated user could exploit this flaw to possibly cause a denial of service.
Statement: This issue does not affect any shipping versions of Red Hat Enterprise Linux kernels. The patch causing the incorrect "double put" condition is not applied to
Debian
CVE-2015-5706: linux - Use-after-free vulnerability in the path_openat function in fs/namei.c in the Li...
vendor_debian·2015·CVSS 4.6
CVE-2015-5706 [MEDIUM] CVE-2015-5706: linux - Use-after-free vulnerability in the path_openat function in fs/namei.c in the Li...
Use-after-free vulnerability in the path_openat function in fs/namei.c in the Linux kernel 3.x and 4.x before 4.0.4 allows local users to cause a denial of service or possibly have unspecified other impact via O_TMPFILE filesystem operations that leverage a duplicate cleanup operation.
Scope: local
bookworm: resolved (fixed in 4.0.4-1)
bullseye: resolved (fixed in 4.0.4-1)
forky: resolved (fixed in 4.0.4-1)
sid: resolved (fixed in 4.0.4-1)
trixie: resolved (fixed in 4.0.4-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-5706 kernel: Use-after-free in path lookup [fedora-all]
bugzilla·2015-08-04·CVSS 4.6
CVE-2015-5706 [MEDIUM] CVE-2015-5706 kernel: Use-after-free in path lookup [fedora-all]
CVE-2015-5706 kernel: Use-after-free in path lookup [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While
Bugzilla
CVE-2015-5706 kernel: Use-after-free in path lookup
bugzilla·2015-08-04·CVSS 4.6
CVE-2015-5706 [MEDIUM] CVE-2015-5706 kernel: Use-after-free in path lookup
CVE-2015-5706 kernel: Use-after-free in path lookup
A flaw was found in the Linux kernels function path_openat() in which would incorrectly clear up twice (as part of path_lookupat() called by
do_tmpfile(). Doing so again can lead to double fput(). This can lead to a use-after free condition.
CVE assignment:
http://seclists.org/oss-sec/2015/q3/270
Introduced in this commit:
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=bb458c644a59dbba3a1fe59b27106c5e68e1c4bd
Upstream patch:
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=f15133df088ecadd141ea1907f2c96df67c729f0
OSS-SEC request:
http://seclists.org/oss-sec/2015/q3/371
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1250048]
---
According to th
arXiv
On the Effectiveness of Function-Level Vulnerability Detectors for Inter-Procedural Vulnerabilities
arxiv_fulltext·2024-01-20
On the Effectiveness of Function-Level Vulnerability Detectors for Inter-Procedural Vulnerabilities
On the Effectiveness of Function-Level Vulnerability Detectors for Inter-Procedural Vulnerabilities
Zhen Li
National Engineering Research Center for Big Data Technology and System, Services Computing Technology and System Lab, Hubei Key Laboratory of Distributed System Security, Hubei Engineering Research Center on Big Data Security, Cluster and Grid Computing Lab
JinYinHu Laboratory, Wuhan, China
School of Cyber Science and Engineering, Huazhong University of Science and Technology
Wuhan
China
[email protected]
Ning Wang
[1]
School of Cyber Science and Engineering, Huazhong University of Science and Technology
Wuhan
China
[email protected]
Deqing Zou
[1]
[2]
Corresponding author
School of Cyber Science and Engineering, Huazhong University of Science and Technology
Wuhan
China
d
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=f15133df088ecadd141ea1907f2c96df67c729f0http://twitter.com/grsecurity/statuses/597127122910490624http://www.debian.org/security/2015/dsa-3329http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.0.4http://www.openwall.com/lists/oss-security/2015/08/01/5http://www.securityfocus.com/bid/76142http://www.ubuntu.com/usn/USN-2680-1http://www.ubuntu.com/usn/USN-2681-1https://bugzilla.redhat.com/show_bug.cgi?id=1250047https://github.com/torvalds/linux/commit/f15133df088ecadd141ea1907f2c96df67c729f0https://source.android.com/security/bulletin/2017-01-01.htmlhttp://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=f15133df088ecadd141ea1907f2c96df67c729f0http://twitter.com/grsecurity/statuses/597127122910490624http://www.debian.org/security/2015/dsa-3329http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.0.4http://www.openwall.com/lists/oss-security/2015/08/01/5http://www.securityfocus.com/bid/76142http://www.ubuntu.com/usn/USN-2680-1http://www.ubuntu.com/usn/USN-2681-1https://bugzilla.redhat.com/show_bug.cgi?id=1250047https://github.com/torvalds/linux/commit/f15133df088ecadd141ea1907f2c96df67c729f0https://source.android.com/security/bulletin/2017-01-01.html
2015-08-31
Published