CVE-2015-5707
published 2015-10-19CVE-2015-5707: Integer overflow in the sg_start_req function in drivers/scsi/sg.c in the Linux kernel 2.6.x through 4.x before 4.1 allows local users to cause a denial of…
PriorityP415medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EPSS
0.49%
39.5th percentile
Integer overflow in the sg_start_req function in drivers/scsi/sg.c in the Linux kernel 2.6.x through 4.x before 4.1 allows local users to cause a denial of service or possibly have unspecified other impact via a large iov_count value in a write request.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | linux | < linux 4.1.3-1 (bookworm) | linux 4.1.3-1 (bookworm) |
| android | — | — | |
| linux | linux_kernel | >= 0 < 4.1.3-1 | 4.1.3-1 |
| linux | linux_kernel | >= 0 < 4.1.3-1 | 4.1.3-1 |
| linux | linux_kernel | >= 0 < 4.1.3-1 | 4.1.3-1 |
| linux | linux_kernel | >= 0 < 4.1.3-1 | 4.1.3-1 |
| linux | linux_kernel | >= 2.6.0 < 4.1.0 | 4.1.0 |
| suse | suse_linux_enterprise_desktop | — | — |
| suse | suse_linux_enterprise_server | — | — |
CVSS provenance
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv4.6MEDIUM
vendor_debian4.6MEDIUM
vendor_redhat4.6MEDIUM
vendor_ubuntu4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2015-5707: SCSI driver
vendor_android·2017-07-01·CVSS 4.6
CVE-2015-5707 [MEDIUM] CVE-2015-5707: SCSI driver
Android Security Bulletin 2017-07-01
CVE: CVE-2015-5707
Severity: MEDIUM
Type: EoP
Component: SCSI driver
References: A-35841297
Upstream kernel
[2]
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2015-10-01·CVSS 4.6
CVE-2015-5707 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that an integer overflow error existed in the SCSI
generic (sg) driver in the Linux kernel. A local attacker with write
permission to a SCSI generic device could use this to cause a denial of
service (system crash) or potentially escalate their privileges.
(CVE-2015-5707)
Marc-André Lureau discovered that the vhost driver did not properly
release the userspace provided log file descriptor. A privileged attacker
could use this to cause a denial of service (resource exhaustion).
(CVE-2015-6252)
It was discovered that the Linux kernel's perf subsystem did not bound
callchain backtraces on PowerPC 64. A local attacker could use this to
cause a denial of service. (CVE-2015-6526)
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2015-10-01·CVSS 4.6
CVE-2015-5707 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that an integer overflow error existed in the SCSI
generic (sg) driver in the Linux kernel. A local attacker with write
permission to a SCSI generic device could use this to cause a denial of
service (system crash) or potentially escalate their privileges.
(CVE-2015-5707)
Marc-André Lureau discovered that the vhost driver did not properly
release the userspace provided log file descriptor. A privileged attacker
could use this to cause a denial of service (resource exhaustion).
(CVE-2015-6252)
It was discovered that the Linux kernel's perf subsystem did not bound
callchain backtraces on PowerPC 64. A local attacker could use this to
cause a denial of service. (CVE-201
Ubuntu
Linux kernel (Utopic HWE) vulnerability
vendor_ubuntu·2015-09-29
CVE-2015-5707 Linux kernel (Utopic HWE) vulnerability
Title: Linux kernel (Utopic HWE) vulnerability
Summary: The system could be made to crash or run programs as an administrator.
It was discovered that an integer overflow error existed in the SCSI
generic (sg) driver in the Linux kernel. A local attacker with write
permission to a SCSI generic device could use this to cause a denial of
service (system crash) or potentially escalate their privileges.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well
Ubuntu
Linux kernel (Vivid HWE) vulnerability
vendor_ubuntu·2015-09-09
CVE-2015-5707 Linux kernel (Vivid HWE) vulnerability
Title: Linux kernel (Vivid HWE) vulnerability
Summary: The system could be made to crash or run programs as an administrator.
It was discovered that an integer overflow error existed in the SCSI
generic (sg) driver in the Linux kernel. A local attacker with write
permission to a SCSI generic device could use this to cause a denial of
service (system crash) or potentially escalate their privileges.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well t
Ubuntu
Linux kernel vulnerability
vendor_ubuntu·2015-09-09
CVE-2015-5707 Linux kernel vulnerability
Title: Linux kernel vulnerability
Summary: The system could be made to crash or run programs as an administrator.
It was discovered that an integer overflow error existed in the SCSI
generic (sg) driver in the Linux kernel. A local attacker with write
permission to a SCSI generic device could use this to cause a denial of
service (system crash) or potentially escalate their privileges.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get module
Ubuntu
Linux kernel (Trusty HWE) vulnerability
vendor_ubuntu·2015-09-03
CVE-2015-5707 Linux kernel (Trusty HWE) vulnerability
Title: Linux kernel (Trusty HWE) vulnerability
Summary: The system could be made to crash or run programs as an administrator.
It was discovered that an integer overflow error existed in the SCSI
generic (sg) driver in the Linux kernel. A local attacker with write
permission to a SCSI generic device could use this to cause a denial of
service (system crash) or potentially escalate their privileges.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well
Red Hat
kernel: number wraparound vulnerability in function start_req()
vendor_redhat·2015-03-22·CVSS 4.6
CVE-2015-5707 [MEDIUM] CWE-190 kernel: number wraparound vulnerability in function start_req()
kernel: number wraparound vulnerability in function start_req()
Integer overflow in the sg_start_req function in drivers/scsi/sg.c in the Linux kernel 2.6.x through 4.x before 4.1 allows local users to cause a denial of service or possibly have unspecified other impact via a large iov_count value in a write request.
An integer-overflow vulnerability was found in the scsi block-request handling code in function start_req(). A local attacker could use specially crafted IOV requests to overflow a counter used in bio_map_user_iov()'s page calculation, and write past the end of the array that contains kernel-page pointers.
Statement: This issue affects the Linux kernels as shipped with Red Hat Enterprise Linux 6, 7 MRG-2 and realtime kernels and does not plan be addressed in a future update.
Debian
CVE-2015-5707: linux - Integer overflow in the sg_start_req function in drivers/scsi/sg.c in the Linux ...
vendor_debian·2015·CVSS 4.6
CVE-2015-5707 [MEDIUM] CVE-2015-5707: linux - Integer overflow in the sg_start_req function in drivers/scsi/sg.c in the Linux ...
Integer overflow in the sg_start_req function in drivers/scsi/sg.c in the Linux kernel 2.6.x through 4.x before 4.1 allows local users to cause a denial of service or possibly have unspecified other impact via a large iov_count value in a write request.
Scope: local
bookworm: resolved (fixed in 4.1.3-1)
bullseye: resolved (fixed in 4.1.3-1)
forky: resolved (fixed in 4.1.3-1)
sid: resolved (fixed in 4.1.3-1)
trixie: resolved (fixed in 4.1.3-1)
GHSA
GHSA-rfcp-m7v6-h4ff: Integer overflow in the sg_start_req function in drivers/scsi/sg
ghsa_unreviewed·2022-05-13
CVE-2015-5707 [MEDIUM] CWE-190 GHSA-rfcp-m7v6-h4ff: Integer overflow in the sg_start_req function in drivers/scsi/sg
Integer overflow in the sg_start_req function in drivers/scsi/sg.c in the Linux kernel 2.6.x through 4.x before 4.1 allows local users to cause a denial of service or possibly have unspecified other impact via a large iov_count value in a write request.
OSV
CVE-2015-5707: Integer overflow in the sg_start_req function in drivers/scsi/sg
osv·2015-10-19·CVSS 4.6
CVE-2015-5707 [MEDIUM] CVE-2015-5707: Integer overflow in the sg_start_req function in drivers/scsi/sg
Integer overflow in the sg_start_req function in drivers/scsi/sg.c in the Linux kernel 2.6.x through 4.x before 4.1 allows local users to cause a denial of service or possibly have unspecified other impact via a large iov_count value in a write request.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-5707 kernel: number wraparound vulnerability in function start_req()
bugzilla·2015-08-04·CVSS 4.6
CVE-2015-5707 [MEDIUM] CVE-2015-5707 kernel: number wraparound vulnerability in function start_req()
CVE-2015-5707 kernel: number wraparound vulnerability in function start_req()
This bug, which was probably introduced in Linux 2.6.28, was assigned CVE.
In drivers/scsi/sg.c in function start_req(), there was code segment vulnerable to number wraparound in the calculation of total number of pages in bio_map_user_iov().
This can result to allocating small array of pointers to pages that would be overflowed. It was fixed in Linux 4.1-rc1.
CVE assignment:
http://seclists.org/oss-sec/2015/q3/278
Upstream patches:
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=fdc81f45e9f57858da6351836507fbcf1b7583ee
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=451a2886b6bf90e2fb378f7c46c655450fb96e81
Discussion:
Created kernel tracking bugs for this
Bugzilla
CVE-2015-5707 kernel: number wraparound vulnerability in function start_req() [fedora-all]
bugzilla·2015-08-04·CVSS 4.6
CVE-2015-5707 [MEDIUM] CVE-2015-5707 kernel: number wraparound vulnerability in function start_req() [fedora-all]
CVE-2015-5707 kernel: number wraparound vulnerability in function start_req() [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=451a2886b6bf90e2fb378f7c46c655450fb96e81http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=fdc81f45e9f57858da6351836507fbcf1b7583eehttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00027.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00028.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00029.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00030.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00031.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00032.htmlhttp://www.debian.org/security/2015/dsa-3329http://www.openwall.com/lists/oss-security/2015/08/01/6http://www.securityfocus.com/bid/76145http://www.securitytracker.com/id/1033521http://www.ubuntu.com/usn/USN-2733-1http://www.ubuntu.com/usn/USN-2734-1http://www.ubuntu.com/usn/USN-2737-1http://www.ubuntu.com/usn/USN-2738-1http://www.ubuntu.com/usn/USN-2750-1http://www.ubuntu.com/usn/USN-2759-1http://www.ubuntu.com/usn/USN-2760-1https://bugzilla.redhat.com/show_bug.cgi?id=1250030https://github.com/torvalds/linux/commit/451a2886b6bf90e2fb378f7c46c655450fb96e81https://github.com/torvalds/linux/commit/fdc81f45e9f57858da6351836507fbcf1b7583eehttps://source.android.com/security/bulletin/2017-07-01http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=451a2886b6bf90e2fb378f7c46c655450fb96e81http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=fdc81f45e9f57858da6351836507fbcf1b7583eehttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00027.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00028.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00029.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00030.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00031.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00032.htmlhttp://www.debian.org/security/2015/dsa-3329http://www.openwall.com/lists/oss-security/2015/08/01/6http://www.securityfocus.com/bid/76145http://www.securitytracker.com/id/1033521http://www.ubuntu.com/usn/USN-2733-1http://www.ubuntu.com/usn/USN-2734-1http://www.ubuntu.com/usn/USN-2737-1http://www.ubuntu.com/usn/USN-2738-1http://www.ubuntu.com/usn/USN-2750-1http://www.ubuntu.com/usn/USN-2759-1http://www.ubuntu.com/usn/USN-2760-1https://bugzilla.redhat.com/show_bug.cgi?id=1250030https://github.com/torvalds/linux/commit/451a2886b6bf90e2fb378f7c46c655450fb96e81https://github.com/torvalds/linux/commit/fdc81f45e9f57858da6351836507fbcf1b7583eehttps://source.android.com/security/bulletin/2017-07-01
2015-10-19
Published