CVE-2015-7799
published 2015-10-19CVE-2015-7799: The slhc_init function in drivers/net/slip/slhc.c in the Linux kernel through 4.2.3 does not ensure that certain slot numbers are valid, which allows local…
PriorityP416medium4.9CVSS 2.0
AVLACLAuNCNINAC
EPSS
0.65%
47.8th percentile
The slhc_init function in drivers/net/slip/slhc.c in the Linux kernel through 4.2.3 does not ensure that certain slot numbers are valid, which allows local users to cause a denial of service (NULL pointer dereference and system crash) via a crafted PPPIOCSMAXCID ioctl call.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.2.6-2 (bookworm) | linux 4.2.6-2 (bookworm) |
| linux | linux_kernel | <= 4.2.2 | — |
| linux | linux_kernel | >= 0 < 4.2.6-2 | 4.2.6-2 |
| linux | linux_kernel | >= 0 < 4.2.6-2 | 4.2.6-2 |
| linux | linux_kernel | >= 0 < 4.2.6-2 | 4.2.6-2 |
| linux | linux_kernel | >= 0 < 4.2.6-2 | 4.2.6-2 |
| linux | linux_kernel | >= 0 < 3.13.0-73.116 | 3.13.0-73.116 |
CVSS provenance
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv4.9MEDIUM
vendor_ubuntu5.3MEDIUM
vendor_debian4.9MEDIUM
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2016-02-01·CVSS 5.3
CVE-2013-7446 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that a use-after-free vulnerability existed in the
AF_UNIX implementation in the Linux kernel. A local attacker could use
crafted epoll_ctl calls to cause a denial of service (system crash) or
expose sensitive information. (CVE-2013-7446)
It was discovered that the KVM implementation in the Linux kernel did not
properly restore the values of the Programmable Interrupt Timer (PIT). A
user-assisted attacker in a KVM guest could cause a denial of service in
the host (system crash). (CVE-2015-7513)
郭永刚 discovered that the ppp implementation in the Linux kernel did
not ensure that certain slot numbers are valid. A local attacker with the
privilege to call ioctl() on /dev/ppp coul
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2016-02-01·CVSS 5.3
CVE-2013-7446 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that a use-after-free vulnerability existed in the
AF_UNIX implementation in the Linux kernel. A local attacker could use
crafted epoll_ctl calls to cause a denial of service (system crash) or
expose sensitive information. (CVE-2013-7446)
It was discovered that the KVM implementation in the Linux kernel did not
properly restore the values of the Programmable Interrupt Timer (PIT). A
user-assisted attacker in a KVM guest could cause a denial of service in
the host (system crash). (CVE-2015-7513)
郭永刚 discovered that the ppp implementation in the Linux kernel did
not ensure that certain slot numbers are valid. A local attacker with the
privilege to call ioctl() on /dev/
Ubuntu
Linux kernel (Wily HWE) vulnerabilities
vendor_ubuntu·2015-12-17·CVSS 4.9
CVE-2015-7799 [MEDIUM] Linux kernel (Wily HWE) vulnerabilities
Title: Linux kernel (Wily HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Jan Beulich discovered that the KVM svm hypervisor implementation in the
Linux kernel did not properly catch Debug exceptions on AMD processors. An
attacker in a guest virtual machine could use this to cause a denial of
service (system crash) in the host OS. (CVE-2015-8104)
郭永刚 discovered that the ppp implementation in the Linux kernel did
not ensure that certain slot numbers are valid. A local attacker with the
privilege to call ioctl() on /dev/ppp could cause a denial of service
(system crash). (CVE-2015-7799)
Dmitry Vyukov discovered that the Linux kernel's keyring handler attempted
to garbage collect incompletely instantiated keys. A local unprivileged
attacker could use this t
Ubuntu
Linux kernel (Vivid HWE) vulnerabilities
vendor_ubuntu·2015-12-17·CVSS 4.9
CVE-2015-7799 [MEDIUM] Linux kernel (Vivid HWE) vulnerabilities
Title: Linux kernel (Vivid HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Jan Beulich discovered that the KVM svm hypervisor implementation in the
Linux kernel did not properly catch Debug exceptions on AMD processors. An
attacker in a guest virtual machine could use this to cause a denial of
service (system crash) in the host OS. (CVE-2015-8104)
郭永刚 discovered that the ppp implementation in the Linux kernel did
not ensure that certain slot numbers are valid. A local attacker with the
privilege to call ioctl() on /dev/ppp could cause a denial of service
(system crash). (CVE-2015-7799)
It was discovered that the virtual video osd test driver in the Linux
kernel did not properly initialize data structures. A local attacker could
use this to obtain sensiti
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2015-12-17·CVSS 4.9
CVE-2015-7799 [MEDIUM] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Jan Beulich discovered that the KVM svm hypervisor implementation in the
Linux kernel did not properly catch Debug exceptions on AMD processors. An
attacker in a guest virtual machine could use this to cause a denial of
service (system crash) in the host OS. (CVE-2015-8104)
郭永刚 discovered that the ppp implementation in the Linux kernel did
not ensure that certain slot numbers are valid. A local attacker with the
privilege to call ioctl() on /dev/ppp could cause a denial of service
(system crash). (CVE-2015-7799)
It was discovered that the driver for Digi Neo and ClassicBoard devices did
not properly initialize data structures. A local attacker could use this to
obtain sensitive i
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2015-12-17·CVSS 4.9
CVE-2015-7799 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Jan Beulich discovered that the KVM svm hypervisor implementation in the
Linux kernel did not properly catch Debug exceptions on AMD processors. An
attacker in a guest virtual machine could use this to cause a denial of
service (system crash) in the host OS. (CVE-2015-8104)
郭永刚 discovered that the ppp implementation in the Linux kernel did
not ensure that certain slot numbers are valid. A local attacker with the
privilege to call ioctl() on /dev/ppp could cause a denial of service
(system crash). (CVE-2015-7799)
Dmitry Vyukov discovered that the Linux kernel's keyring handler attempted
to garbage collect incompletely instantiated keys. A local unprivileged
attacker could use this to cause a d
Ubuntu
Linux kernel (Utopic HWE) vulnerabilities
vendor_ubuntu·2015-12-17·CVSS 4.9
CVE-2015-7799 [MEDIUM] Linux kernel (Utopic HWE) vulnerabilities
Title: Linux kernel (Utopic HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Jan Beulich discovered that the KVM svm hypervisor implementation in the
Linux kernel did not properly catch Debug exceptions on AMD processors. An
attacker in a guest virtual machine could use this to cause a denial of
service (system crash) in the host OS. (CVE-2015-8104)
郭永刚 discovered that the ppp implementation in the Linux kernel did
not ensure that certain slot numbers are valid. A local attacker with the
privilege to call ioctl() on /dev/ppp could cause a denial of service
(system crash). (CVE-2015-7799)
It was discovered that the driver for Digi Neo and ClassicBoard devices did
not properly initialize data structures. A local attacker could use this to
obtain sensitive i
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2015-12-17·CVSS 4.9
CVE-2015-7799 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Jan Beulich discovered that the KVM svm hypervisor implementation in the
Linux kernel did not properly catch Debug exceptions on AMD processors. An
attacker in a guest virtual machine could use this to cause a denial of
service (system crash) in the host OS. (CVE-2015-8104)
郭永刚 discovered that the ppp implementation in the Linux kernel did
not ensure that certain slot numbers are valid. A local attacker with the
privilege to call ioctl() on /dev/ppp could cause a denial of service
(system crash). (CVE-2015-7799)
It was discovered that the virtual video osd test driver in the Linux
kernel did not properly initialize data structures. A local attacker could
use this to obtain sensitive informati
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2015-12-17·CVSS 4.9
CVE-2015-7799 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Jan Beulich discovered that the KVM svm hypervisor implementation in the
Linux kernel did not properly catch Debug exceptions on AMD processors. An
attacker in a guest virtual machine could use this to cause a denial of
service (system crash) in the host OS. (CVE-2015-8104)
郭永刚 discovered that the ppp implementation in the Linux kernel did
not ensure that certain slot numbers are valid. A local attacker with the
privilege to call ioctl() on /dev/ppp could cause a denial of service
(system crash). (CVE-2015-7799)
It was discovered that the driver for Digi Neo and ClassicBoard devices did
not properly initialize data structures. A local attacker could use this to
obtain sensitive information fr
Red Hat
kernel: net: slip: crash when using PPP character device driver
vendor_redhat·2015-10-08·CVSS 4.9
CVE-2015-7799 [MEDIUM] CWE-476 kernel: net: slip: crash when using PPP character device driver
kernel: net: slip: crash when using PPP character device driver
The slhc_init function in drivers/net/slip/slhc.c in the Linux kernel through 4.2.3 does not ensure that certain slot numbers are valid, which allows local users to cause a denial of service (NULL pointer dereference and system crash) via a crafted PPPIOCSMAXCID ioctl call.
A flaw was discovered in the Linux kernel where issuing certain ioctl() -s commands to the "/dev/ppp" device file could lead to a NULL pointer dereference. A privileged user could use this flaw to cause a kernel crash and denial of service.
Statement: This issue affects the Linux kernel packages as shipped with Red Hat Enterprise Linux 5, 6, 7 and MRG-2.
This has been rated as having Low security impact as privileged access is required to exploit it, and
Debian
CVE-2015-7799: linux - The slhc_init function in drivers/net/slip/slhc.c in the Linux kernel through 4....
vendor_debian·2015·CVSS 4.9
CVE-2015-7799 [MEDIUM] CVE-2015-7799: linux - The slhc_init function in drivers/net/slip/slhc.c in the Linux kernel through 4....
The slhc_init function in drivers/net/slip/slhc.c in the Linux kernel through 4.2.3 does not ensure that certain slot numbers are valid, which allows local users to cause a denial of service (NULL pointer dereference and system crash) via a crafted PPPIOCSMAXCID ioctl call.
Scope: local
bookworm: resolved (fixed in 4.2.6-2)
bullseye: resolved (fixed in 4.2.6-2)
forky: resolved (fixed in 4.2.6-2)
sid: resolved (fixed in 4.2.6-2)
trixie: resolved (fixed in 4.2.6-2)
GHSA
GHSA-4r89-qcc9-4pm9: The slhc_init function in drivers/net/slip/slhc
ghsa_unreviewed·2022-05-17
CVE-2015-7799 [MEDIUM] GHSA-4r89-qcc9-4pm9: The slhc_init function in drivers/net/slip/slhc
The slhc_init function in drivers/net/slip/slhc.c in the Linux kernel through 4.2.3 does not ensure that certain slot numbers are valid, which allows local users to cause a denial of service (NULL pointer dereference and system crash) via a crafted PPPIOCSMAXCID ioctl call.
OSV
linux vulnerabilities
osv·2015-12-17·CVSS 4.9
CVE-2015-8104 [MEDIUM] linux vulnerabilities
linux vulnerabilities
Jan Beulich discovered that the KVM svm hypervisor implementation in the
Linux kernel did not properly catch Debug exceptions on AMD processors. An
attacker in a guest virtual machine could use this to cause a denial of
service (system crash) in the host OS. (CVE-2015-8104)
郭永刚 discovered that the ppp implementation in the Linux kernel did
not ensure that certain slot numbers are valid. A local attacker with the
privilege to call ioctl() on /dev/ppp could cause a denial of service
(system crash). (CVE-2015-7799)
It was discovered that the driver for Digi Neo and ClassicBoard devices did
not properly initialize data structures. A local attacker could use this to
obtain sensitive information from the kernel. (CVE-2015-7885)
OSV
linux-lts-utopic vulnerabilities
osv·2015-12-17·CVSS 4.9
CVE-2015-8104 [MEDIUM] linux-lts-utopic vulnerabilities
linux-lts-utopic vulnerabilities
Jan Beulich discovered that the KVM svm hypervisor implementation in the
Linux kernel did not properly catch Debug exceptions on AMD processors. An
attacker in a guest virtual machine could use this to cause a denial of
service (system crash) in the host OS. (CVE-2015-8104)
郭永刚 discovered that the ppp implementation in the Linux kernel did
not ensure that certain slot numbers are valid. A local attacker with the
privilege to call ioctl() on /dev/ppp could cause a denial of service
(system crash). (CVE-2015-7799)
It was discovered that the driver for Digi Neo and ClassicBoard devices did
not properly initialize data structures. A local attacker could use this to
obtain sensitive information from the kernel. (CVE-2015-7885)
OSV
linux-lts-wily vulnerabilities
osv·2015-12-17·CVSS 4.9
CVE-2015-8104 [MEDIUM] linux-lts-wily vulnerabilities
linux-lts-wily vulnerabilities
Jan Beulich discovered that the KVM svm hypervisor implementation in the
Linux kernel did not properly catch Debug exceptions on AMD processors. An
attacker in a guest virtual machine could use this to cause a denial of
service (system crash) in the host OS. (CVE-2015-8104)
郭永刚 discovered that the ppp implementation in the Linux kernel did
not ensure that certain slot numbers are valid. A local attacker with the
privilege to call ioctl() on /dev/ppp could cause a denial of service
(system crash). (CVE-2015-7799)
Dmitry Vyukov discovered that the Linux kernel's keyring handler attempted
to garbage collect incompletely instantiated keys. A local unprivileged
attacker could use this to cause a denial of service (system crash).
(CVE-2015-7872)
It was discover
OSV
linux-lts-vivid vulnerabilities
osv·2015-12-17·CVSS 4.9
CVE-2015-8104 [MEDIUM] linux-lts-vivid vulnerabilities
linux-lts-vivid vulnerabilities
Jan Beulich discovered that the KVM svm hypervisor implementation in the
Linux kernel did not properly catch Debug exceptions on AMD processors. An
attacker in a guest virtual machine could use this to cause a denial of
service (system crash) in the host OS. (CVE-2015-8104)
郭永刚 discovered that the ppp implementation in the Linux kernel did
not ensure that certain slot numbers are valid. A local attacker with the
privilege to call ioctl() on /dev/ppp could cause a denial of service
(system crash). (CVE-2015-7799)
It was discovered that the virtual video osd test driver in the Linux
kernel did not properly initialize data structures. A local attacker could
use this to obtain sensitive information from the kernel. (CVE-2015-7884)
It was discovered that the
Kernel
ppp, slip: Validate VJ compression slot parameters completely
kernel_security·2015-11-01·CVSS 4.9
CVE-2015-7799 [MEDIUM] ppp, slip: Validate VJ compression slot parameters completely
ppp, slip: Validate VJ compression slot parameters completely
Currently slhc_init() treats out-of-range values of rslots and tslots
as equivalent to 0, except that if tslots is too large it will
dereference a null pointer (CVE-2015-7799).
Add a range-check at the top of the function and make it return an
ERR_PTR() on error instead of NULL. Change the callers accordingly.
Compile-tested only.
Reported-by: 郭永刚
References: http://article.gmane.org/gmane.comp.security.oss.general/17908
Signed-off-by: Ben Hutchings
Signed-off-by: David S. Miller
OSV
CVE-2015-7799: The slhc_init function in drivers/net/slip/slhc
osv·2015-10-19·CVSS 4.9
CVE-2015-7799 [MEDIUM] CVE-2015-7799: The slhc_init function in drivers/net/slip/slhc
The slhc_init function in drivers/net/slip/slhc.c in the Linux kernel through 4.2.3 does not ensure that certain slot numbers are valid, which allows local users to cause a denial of service (NULL pointer dereference and system crash) via a crafted PPPIOCSMAXCID ioctl call.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-7799 kernel: net: slip: crash when using PPP character device driver [fedora-all]
bugzilla·2015-10-13·CVSS 4.9
CVE-2015-7799 [MEDIUM] CVE-2015-7799 kernel: net: slip: crash when using PPP character device driver [fedora-all]
CVE-2015-7799 kernel: net: slip: crash when using PPP character device driver [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported
Bugzilla
CVE-2015-7799 kernel: net: slip: crash when using PPP character device driver
bugzilla·2015-10-13·CVSS 4.9
CVE-2015-7799 [MEDIUM] CVE-2015-7799 kernel: net: slip: crash when using PPP character device driver
CVE-2015-7799 kernel: net: slip: crash when using PPP character device driver
The following flaw was found in the Linux kernel:
In the process of using the PPP device driver, if the unit of the PPP device file has been created. On the basis of the above, the ioctl function is used to pass the PPPIOCSMAXCID command and the 0x67084000 parameter (parameters must be satisfied: arg>>16 > 255 and 0xFFFF&arg > 255), which will lead to the use of null pointers in the kernel.
References:
https://code.google.com/p/android/issues/detail?id=187973
http://seclists.org/oss-sec/2015/q4/53
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/drivers/net/slip/slhc.c?id=4ab42d78e37a294ac7bc56901d563c642e03c4ae
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-a
http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00031.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00038.htmlhttp://lists.opensuse.org/opensuse-updates/2015-12/msg00039.htmlhttp://www.debian.org/security/2015/dsa-3426http://www.openwall.com/lists/oss-security/2015/10/10/3http://www.securityfocus.com/bid/77033http://www.securitytracker.com/id/1033809http://www.ubuntu.com/usn/USN-2841-1http://www.ubuntu.com/usn/USN-2841-2http://www.ubuntu.com/usn/USN-2842-1http://www.ubuntu.com/usn/USN-2842-2http://www.ubuntu.com/usn/USN-2843-1http://www.ubuntu.com/usn/USN-2843-2http://www.ubuntu.com/usn/USN-2843-3http://www.ubuntu.com/usn/USN-2844-1http://www.ubuntu.com/usn/USN-2886-1https://bugzilla.redhat.com/show_bug.cgi?id=1271134https://code.google.com/p/android/issues/detail?id=187973http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00031.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00038.htmlhttp://lists.opensuse.org/opensuse-updates/2015-12/msg00039.htmlhttp://www.debian.org/security/2015/dsa-3426http://www.openwall.com/lists/oss-security/2015/10/10/3http://www.securityfocus.com/bid/77033http://www.securitytracker.com/id/1033809http://www.ubuntu.com/usn/USN-2841-1http://www.ubuntu.com/usn/USN-2841-2http://www.ubuntu.com/usn/USN-2842-1http://www.ubuntu.com/usn/USN-2842-2http://www.ubuntu.com/usn/USN-2843-1http://www.ubuntu.com/usn/USN-2843-2http://www.ubuntu.com/usn/USN-2843-3http://www.ubuntu.com/usn/USN-2844-1http://www.ubuntu.com/usn/USN-2886-1https://bugzilla.redhat.com/show_bug.cgi?id=1271134https://code.google.com/p/android/issues/detail?id=187973
2015-10-19
Published