CVE-2015-6937
published 2015-10-19CVE-2015-6937: The __rds_conn_create function in net/rds/connection.c in the Linux kernel through 4.2.3 allows local users to cause a denial of service (NULL pointer…
PriorityP415medium4.9CVSS 2.0
AVLACLAuNCNINAC
EPSS
0.52%
41.3th percentile
The __rds_conn_create function in net/rds/connection.c in the Linux kernel through 4.2.3 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by using a socket that was not properly bound.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | linux | < linux 4.2.6-1 (bookworm) | linux 4.2.6-1 (bookworm) |
| debian | linux | < linux 4.2.1-1 (bookworm) | linux 4.2.1-1 (bookworm) |
| linux | linux_kernel | <= 4.2.3 | — |
| linux | linux_kernel | <= 4.3.2 | — |
| linux | linux_kernel | >= 0 < 4.2.1-1 | 4.2.1-1 |
| linux | linux_kernel | >= 0 < 4.2.6-1 | 4.2.6-1 |
| linux | linux_kernel | >= 0 < 4.2.1-1 | 4.2.1-1 |
| linux | linux_kernel | >= 0 < 4.2.6-1 | 4.2.6-1 |
| linux | linux_kernel | >= 0 < 4.2.1-1 | 4.2.1-1 |
| linux | linux_kernel | >= 0 < 4.2.6-1 | 4.2.6-1 |
| linux | linux_kernel | >= 0 < 4.2.1-1 | 4.2.1-1 |
| linux | linux_kernel | >= 0 < 4.2.6-1 | 4.2.6-1 |
| linux | linux_kernel | >= 0 < 3.13.0-66.108 | 3.13.0-66.108 |
CVSS provenance
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv6.1MEDIUM
vendor_ubuntu6.1MEDIUM
vendor_debian4.9MEDIUM
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (Utopic HWE) vulnerabilities
vendor_ubuntu·2015-10-20·CVSS 6.1
CVE-2015-5156 [MEDIUM] Linux kernel (Utopic HWE) vulnerabilities
Title: Linux kernel (Utopic HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that virtio networking in the Linux kernel did not handle
fragments correctly, leading to kernel memory corruption. A remote attacker
could use this to cause a denial of service (system crash) or possibly
execute code with administrative privileges. (CVE-2015-5156)
Benjamin Randazzo discovered an information leak in the md (multiple
device) driver when the bitmap_info.file is disabled. A local privileged
attacker could use this to obtain sensitive information from the kernel.
(CVE-2015-5697)
Marc-André Lureau discovered that the vhost driver did not properly
release the userspace provided log file descriptor. A privileged attacker
could use this to cause a denia
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2015-10-20·CVSS 5.0
CVE-2015-0272 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that the Linux kernel did not check if a new IPv6 MTU set
by a user space application was valid. A remote attacker could forge a
route advertisement with an invalid MTU that a user space daemon like
NetworkManager would honor and apply to the kernel, causing a denial of
service. (CVE-2015-0272)
It was discovered that virtio networking in the Linux kernel did not handle
fragments correctly, leading to kernel memory corruption. A remote attacker
could use this to cause a denial of service (system crash) or possibly
execute code with administrative privileges. (CVE-2015-5156)
It was discovered that the Reliable Datagram Sockets (RDS) implementation
in the Linux kernel did not v
Ubuntu
Linux kernel (Vivid HWE) vulnerabilities
vendor_ubuntu·2015-10-20·CVSS 5.0
CVE-2015-0272 [MEDIUM] Linux kernel (Vivid HWE) vulnerabilities
Title: Linux kernel (Vivid HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that the Linux kernel did not check if a new IPv6 MTU set
by a user space application was valid. A remote attacker could forge a
route advertisement with an invalid MTU that a user space daemon like
NetworkManager would honor and apply to the kernel, causing a denial of
service. (CVE-2015-0272)
It was discovered that virtio networking in the Linux kernel did not handle
fragments correctly, leading to kernel memory corruption. A remote attacker
could use this to cause a denial of service (system crash) or possibly
execute code with administrative privileges. (CVE-2015-5156)
It was discovered that the Reliable Datagram Sockets (RDS) implementation
in the Linux kern
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2015-10-19·CVSS 6.1
CVE-2015-5156 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that virtio networking in the Linux kernel did not handle
fragments correctly, leading to kernel memory corruption. A remote attacker
could use this to cause a denial of service (system crash) or possibly
execute code with administrative privileges. (CVE-2015-5156)
It was discovered that the Reliable Datagram Sockets (RDS) implementation
in the Linux kernel did not verify sockets were properly bound before
attempting to send a message, which could cause a NULL pointer dereference.
An attacker could use this to cause a denial of service (system crash).
(CVE-2015-6937)
Instructions: After a standard system update you need to reboot your computer to make
all the necessa
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2015-10-19·CVSS 6.1
CVE-2015-5156 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that virtio networking in the Linux kernel did not handle
fragments correctly, leading to kernel memory corruption. A remote attacker
could use this to cause a denial of service (system crash) or possibly
execute code with administrative privileges. (CVE-2015-5156)
It was discovered that the Reliable Datagram Sockets (RDS) implementation
in the Linux kernel did not verify sockets were properly bound before
attempting to send a message, which could cause a NULL pointer dereference.
An attacker could use this to cause a denial of service (system crash).
(CVE-2015-6937)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary chang
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2015-10-19·CVSS 5.0
CVE-2015-0272 [MEDIUM] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that the Linux kernel did not check if a new IPv6 MTU set
by a user space application was valid. A remote attacker could forge a
route advertisement with an invalid MTU that a user space daemon like
NetworkManager would honor and apply to the kernel, causing a denial of
service. (CVE-2015-0272)
It was discovered that virtio networking in the Linux kernel did not handle
fragments correctly, leading to kernel memory corruption. A remote attacker
could use this to cause a denial of service (system crash) or possibly
execute code with administrative privileges. (CVE-2015-5156)
It was discovered that the Reliable Datagram Sockets (RDS) implementation
in the Linux ker
Red Hat
kernel: Race condition when sending message on unbound socket causing NULL pointer dereference
vendor_redhat·2015-10-16·CVSS 4.9
CVE-2015-7990 [MEDIUM] CWE-476 kernel: Race condition when sending message on unbound socket causing NULL pointer dereference
kernel: Race condition when sending message on unbound socket causing NULL pointer dereference
Race condition in the rds_sendmsg function in net/rds/sendmsg.c in the Linux kernel before 4.3.3 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by using a socket that was not properly bound. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-6937.
A denial of service flaw was discovered in the Linux kernel, where a race condition caused a NULL pointer dereference in the RDS socket-creation code. A local attacker could use this flaw to create a situation in which a NULL pointer crashed the kernel.
Statement: This issue affects Red Hat enterprise Linux 5 and 6. The affected code is not a
Red Hat
kernel: net: rds: NULL pointer dereference in net/rds/connection.c
vendor_redhat·2015-09-14·CVSS 4.9
CVE-2015-6937 [MEDIUM] CWE-476 kernel: net: rds: NULL pointer dereference in net/rds/connection.c
kernel: net: rds: NULL pointer dereference in net/rds/connection.c
The __rds_conn_create function in net/rds/connection.c in the Linux kernel through 4.2.3 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by using a socket that was not properly bound.
A NULL-pointer dereference vulnerability was discovered in the Linux kernel. The kernel's Reliable Datagram Sockets (RDS) protocol implementation did not verify that an underlying transport existed before creating a connection to a remote server. A local system user could exploit this flaw to crash the system by creating sockets at specific times to trigger a NULL pointer dereference.
Statement: This issue did not affect kernel, kernel-rt, and realtime-ker
Debian
CVE-2015-7990: linux - Race condition in the rds_sendmsg function in net/rds/sendmsg.c in the Linux ker...
vendor_debian·2015·CVSS 4.9
CVE-2015-7990 [MEDIUM] CVE-2015-7990: linux - Race condition in the rds_sendmsg function in net/rds/sendmsg.c in the Linux ker...
Race condition in the rds_sendmsg function in net/rds/sendmsg.c in the Linux kernel before 4.3.3 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by using a socket that was not properly bound. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-6937.
Scope: local
bookworm: resolved (fixed in 4.2.6-1)
bullseye: resolved (fixed in 4.2.6-1)
forky: resolved (fixed in 4.2.6-1)
sid: resolved (fixed in 4.2.6-1)
trixie: resolved (fixed in 4.2.6-1)
Debian
CVE-2015-6937: linux - The __rds_conn_create function in net/rds/connection.c in the Linux kernel throu...
vendor_debian·2015·CVSS 4.9
CVE-2015-6937 [MEDIUM] CVE-2015-6937: linux - The __rds_conn_create function in net/rds/connection.c in the Linux kernel throu...
The __rds_conn_create function in net/rds/connection.c in the Linux kernel through 4.2.3 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by using a socket that was not properly bound.
Scope: local
bookworm: resolved (fixed in 4.2.1-1)
bullseye: resolved (fixed in 4.2.1-1)
forky: resolved (fixed in 4.2.1-1)
sid: resolved (fixed in 4.2.1-1)
trixie: resolved (fixed in 4.2.1-1)
GHSA
GHSA-vcw3-c24j-h6v5: The __rds_conn_create function in net/rds/connection
ghsa_unreviewed·2022-05-14
CVE-2015-6937 [MEDIUM] GHSA-vcw3-c24j-h6v5: The __rds_conn_create function in net/rds/connection
The __rds_conn_create function in net/rds/connection.c in the Linux kernel through 4.2.3 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by using a socket that was not properly bound.
GHSA
GHSA-ggf3-232m-5283: Race condition in the rds_sendmsg function in net/rds/sendmsg
ghsa_unreviewed·2022-05-14·CVSS 4.9
CVE-2015-7990 [MEDIUM] CWE-362 GHSA-ggf3-232m-5283: Race condition in the rds_sendmsg function in net/rds/sendmsg
Race condition in the rds_sendmsg function in net/rds/sendmsg.c in the Linux kernel before 4.3.3 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by using a socket that was not properly bound. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-6937.
OSV
CVE-2015-7990: Race condition in the rds_sendmsg function in net/rds/sendmsg
osv·2015-12-28·CVSS 4.9
CVE-2015-7990 [MEDIUM] CVE-2015-7990: Race condition in the rds_sendmsg function in net/rds/sendmsg
Race condition in the rds_sendmsg function in net/rds/sendmsg.c in the Linux kernel before 4.3.3 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by using a socket that was not properly bound. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-6937.
Kernel
RDS: fix race condition when sending a message on unbound socket
kernel_security·2015-11-24·CVSS 4.9
CVE-2015-6937 [MEDIUM] RDS: fix race condition when sending a message on unbound socket
RDS: fix race condition when sending a message on unbound socket
Sasha's found a NULL pointer dereference in the RDS connection code when
sending a message to an apparently unbound socket. The problem is caused
by the code checking if the socket is bound in rds_sendmsg(), which checks
the rs_bound_addr field without taking a lock on the socket. This opens a
race where rs_bound_addr is temporarily set but where the transport is not
in rds_bind(), leading to a NULL pointer dereference when trying to
dereference 'trans' in __rds_conn_create().
Vegard wrote a reproducer for this issue, so kindly ask him to share if
you're interested.
I cannot reproduce the NULL pointer dereference using Vegard's reproducer
with this patch, whereas I could without.
Complete earlier incomplete fix to CVE-201
OSV
linux-lts-utopic vulnerabilities
osv·2015-10-20·CVSS 6.1
CVE-2015-5156 [MEDIUM] linux-lts-utopic vulnerabilities
linux-lts-utopic vulnerabilities
It was discovered that virtio networking in the Linux kernel did not handle
fragments correctly, leading to kernel memory corruption. A remote attacker
could use this to cause a denial of service (system crash) or possibly
execute code with administrative privileges. (CVE-2015-5156)
Benjamin Randazzo discovered an information leak in the md (multiple
device) driver when the bitmap_info.file is disabled. A local privileged
attacker could use this to obtain sensitive information from the kernel.
(CVE-2015-5697)
Marc-André Lureau discovered that the vhost driver did not properly
release the userspace provided log file descriptor. A privileged attacker
could use this to cause a denial of service (resource exhaustion).
(CVE-2015-6252)
It was discovered that
OSV
linux-lts-vivid vulnerabilities
osv·2015-10-20·CVSS 5.0
CVE-2015-0272 [MEDIUM] linux-lts-vivid vulnerabilities
linux-lts-vivid vulnerabilities
It was discovered that the Linux kernel did not check if a new IPv6 MTU set
by a user space application was valid. A remote attacker could forge a
route advertisement with an invalid MTU that a user space daemon like
NetworkManager would honor and apply to the kernel, causing a denial of
service. (CVE-2015-0272)
It was discovered that virtio networking in the Linux kernel did not handle
fragments correctly, leading to kernel memory corruption. A remote attacker
could use this to cause a denial of service (system crash) or possibly
execute code with administrative privileges. (CVE-2015-5156)
It was discovered that the Reliable Datagram Sockets (RDS) implementation
in the Linux kernel did not verify sockets were properly bound before
attempting to send a me
OSV
CVE-2015-6937: The __rds_conn_create function in net/rds/connection
osv·2015-10-19·CVSS 4.9
CVE-2015-6937 [MEDIUM] CVE-2015-6937: The __rds_conn_create function in net/rds/connection
The __rds_conn_create function in net/rds/connection.c in the Linux kernel through 4.2.3 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by using a socket that was not properly bound.
OSV
linux vulnerabilities
osv·2015-10-19·CVSS 5.0
CVE-2015-0272 [MEDIUM] linux vulnerabilities
linux vulnerabilities
It was discovered that the Linux kernel did not check if a new IPv6 MTU set
by a user space application was valid. A remote attacker could forge a
route advertisement with an invalid MTU that a user space daemon like
NetworkManager would honor and apply to the kernel, causing a denial of
service. (CVE-2015-0272)
It was discovered that virtio networking in the Linux kernel did not handle
fragments correctly, leading to kernel memory corruption. A remote attacker
could use this to cause a denial of service (system crash) or possibly
execute code with administrative privileges. (CVE-2015-5156)
It was discovered that the Reliable Datagram Sockets (RDS) implementation
in the Linux kernel did not verify sockets were properly bound before
attempting to send a message, whi
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-7990 kernel: Race condition when sending message on unbound socket causing NULL pointer dereference
bugzilla·2015-10-29·CVSS 4.9
CVE-2015-7990 [MEDIUM] CVE-2015-7990 kernel: Race condition when sending message on unbound socket causing NULL pointer dereference
CVE-2015-7990 kernel: Race condition when sending message on unbound socket causing NULL pointer dereference
A NULL pointer dereference in the RDS connection code when sending a message to an apparently unbound socket in net/rds/connection.c was found. The problem is caused by the code checking if the socket is bound in rds_sendmsg(), which checks the rs_bound_addr field without taking a lock on the socket. This opens a race where rs_bound_addr is temporarily set but where the transport is not in rds_bind(), leading to a NULL pointer dereference when trying to dereference 'trans' in __rds_conn_create().
Note that this is a complete fix of CVE-2015-6937 issue.
Patch can be found here:
https://lkml.org/lkml/2015/10/16/530
CVE assignment:
http://seclists.org/oss-sec/2015/q4/179
Workaro
Bugzilla
CVE-2015-6937 kernel: net: rds: NULL pointer dereference in net/rds/connection.c
bugzilla·2015-09-15·CVSS 4.9
CVE-2015-6937 [MEDIUM] CVE-2015-6937 kernel: net: rds: NULL pointer dereference in net/rds/connection.c
CVE-2015-6937 kernel: net: rds: NULL pointer dereference in net/rds/connection.c
It was found that the Linux kernel's Reliable Datagram Sockets (RDS) protocol implementation did not verify that an underlying transport exists when creating a connection to a remote server.
This could happen on sockets that were not properly bound before attempting to send a message.
A local attacker could use this flaw to crash the system by creating sockets at specific times to trigger a NULL pointer dereference on the system.
Upstream patch:
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=74e98eb085889b0d2d4908f59f6e00026063014f
CVE assignment:
http://seclists.org/oss-sec/2015/q3/545
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 12631
Bugzilla
CVE-2015-6937 kernel: net: rds: NULL pointer dereference in net/rds/connection.c [fedora-all]
bugzilla·2015-09-15·CVSS 4.9
CVE-2015-6937 [MEDIUM] CVE-2015-6937 kernel: net: rds: NULL pointer dereference in net/rds/connection.c [fedora-all]
CVE-2015-6937 kernel: net: rds: NULL pointer dereference in net/rds/connection.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple suppor
arXiv
Characteristics, Root Causes, and Detection of Incomplete Security Bug Fixes in the Linux Kernel
arxiv_fulltext·2025-11-21
Characteristics, Root Causes, and Detection of Incomplete Security Bug Fixes in the Linux Kernel
Characteristics, Root Causes, and Detection of
Incomplete Security Bug Fixes in the Linux Kernel
Qiang Liu^1All work was done by Aug., 2022.,
Wenlong Zhang^1,
Muhui Jiang^2,1,
Lei Wu^1,
Yajin Zhou^1
^1Zhejiang University,
^2The Hong Kong Polytechnic University
## Abstract
Security bugs in the Linux kernel emerge endlessly and have attracted much
attention.
However, fixing security bugs in the Linux kernel could be incomplete due to
human mistakes.
Specifically, an incomplete fix fails to repair all the original security
defects in the software, fails to properly repair the original security defects,
or introduces new ones.
In this paper, we study the fixes of incomplete security bugs in the Linux
kernel for the first time, and reveal their characteristics, root causes as well
as de
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=74e98eb085889b0d2d4908f59f6e00026063014fhttp://lists.fedoraproject.org/pipermail/package-announce/2015-October/168447.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-October/168539.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/167358.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-10/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00035.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00031.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00013.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00017.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00019.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00022.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00034.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00038.htmlhttp://lists.opensuse.org/opensuse-updates/2015-12/msg00039.htmlhttp://www.debian.org/security/2015/dsa-3364http://www.openwall.com/lists/oss-security/2015/09/14/3http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/76767http://www.securitytracker.com/id/1034453http://www.ubuntu.com/usn/USN-2773-1http://www.ubuntu.com/usn/USN-2774-1http://www.ubuntu.com/usn/USN-2777-1https://bugzilla.redhat.com/show_bug.cgi?id=1263139https://github.com/torvalds/linux/commit/74e98eb085889b0d2d4908f59f6e00026063014fhttp://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=74e98eb085889b0d2d4908f59f6e00026063014fhttp://lists.fedoraproject.org/pipermail/package-announce/2015-October/168447.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-October/168539.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/167358.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-10/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00035.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00031.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00013.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00017.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00019.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00022.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00034.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00038.htmlhttp://lists.opensuse.org/opensuse-updates/2015-12/msg00039.htmlhttp://www.debian.org/security/2015/dsa-3364http://www.openwall.com/lists/oss-security/2015/09/14/3http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/76767http://www.securitytracker.com/id/1034453http://www.ubuntu.com/usn/USN-2773-1http://www.ubuntu.com/usn/USN-2774-1http://www.ubuntu.com/usn/USN-2777-1https://bugzilla.redhat.com/show_bug.cgi?id=1263139https://github.com/torvalds/linux/commit/74e98eb085889b0d2d4908f59f6e00026063014f
2015-10-19
Published