cbcvebase.
CVE-2015-6937
published 2015-10-19

CVE-2015-6937: The __rds_conn_create function in net/rds/connection.c in the Linux kernel through 4.2.3 allows local users to cause a denial of service (NULL pointer…

PriorityP415medium4.9CVSS 2.0
AVLACLAuNCNINAC
EPSS
0.52%
41.3th percentile
The __rds_conn_create function in net/rds/connection.c in the Linux kernel through 4.2.3 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by using a socket that was not properly bound.

Affected

17 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debianlinux< linux 4.2.6-1 (bookworm)linux 4.2.6-1 (bookworm)
debianlinux< linux 4.2.1-1 (bookworm)linux 4.2.1-1 (bookworm)
linuxlinux_kernel<= 4.2.3
linuxlinux_kernel<= 4.3.2
linuxlinux_kernel>= 0 < 4.2.1-14.2.1-1
linuxlinux_kernel>= 0 < 4.2.6-14.2.6-1
linuxlinux_kernel>= 0 < 4.2.1-14.2.1-1
linuxlinux_kernel>= 0 < 4.2.6-14.2.6-1
linuxlinux_kernel>= 0 < 4.2.1-14.2.1-1
linuxlinux_kernel>= 0 < 4.2.6-14.2.6-1
linuxlinux_kernel>= 0 < 4.2.1-14.2.1-1
linuxlinux_kernel>= 0 < 4.2.6-14.2.6-1
linuxlinux_kernel>= 0 < 3.13.0-66.1083.13.0-66.108

CVSS provenance

nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv6.1MEDIUM
vendor_ubuntu6.1MEDIUM
vendor_debian4.9MEDIUM
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.