cbcvebase.
CVE-2015-7613
published 2015-10-19

CVE-2015-7613: Race condition in the IPC object implementation in the Linux kernel through 4.2.3 allows local users to gain privileges by triggering an ipc_addid call that…

PriorityP425medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
0.41%
33.9th percentile
Race condition in the IPC object implementation in the Linux kernel through 4.2.3 allows local users to gain privileges by triggering an ipc_addid call that leads to uid and gid comparisons against uninitialized data, related to msg.c, shm.c, and util.c.

Affected

15 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 4.2.3-1 (bookworm)linux 4.2.3-1 (bookworm)
googleandroid
linuxlinux_kernel< 3.2.723.2.72
linuxlinux_kernel>= 0 < 4.2.3-14.2.3-1
linuxlinux_kernel>= 0 < 4.2.3-14.2.3-1
linuxlinux_kernel>= 0 < 4.2.3-14.2.3-1
linuxlinux_kernel>= 0 < 4.2.3-14.2.3-1
linuxlinux_kernel>= 3.11 < 3.12.503.12.50
linuxlinux_kernel>= 3.13 < 3.14.553.14.55
linuxlinux_kernel>= 3.15 < 3.16.353.16.35
linuxlinux_kernel>= 3.17 < 3.18.233.18.23
linuxlinux_kernel>= 3.19 < 4.1.114.1.11
linuxlinux_kernel>= 3.3 < 3.4.1113.4.111
linuxlinux_kernel>= 3.5 < 3.10.913.10.91
linuxlinux_kernel>= 4.2 < 4.2.44.2.4

CVSS provenance

nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv6.9MEDIUM
vendor_debian6.9MEDIUM
vendor_redhat6.9MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.