CVE-2015-8575
published 2016-02-08CVE-2015-8575: The sco_sock_bind function in net/bluetooth/sco.c in the Linux kernel before 4.3.4 does not verify an address length, which allows local users to obtain…
PriorityP415medium4CVSS 3.0
AVLACLPRNUINSUCLINAN
EPSS
0.52%
41.2th percentile
The sco_sock_bind function in net/bluetooth/sco.c in the Linux kernel before 4.3.4 does not verify an address length, which allows local users to obtain sensitive information from kernel memory and bypass the KASLR protection mechanism via a crafted application.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.3.3-3 (bookworm) | linux 4.3.3-3 (bookworm) |
| linux | linux_kernel | <= 4.3.3 | — |
| linux | linux_kernel | >= 0 < 4.3.3-3 | 4.3.3-3 |
| linux | linux_kernel | >= 0 < 4.3.3-3 | 4.3.3-3 |
| linux | linux_kernel | >= 0 < 4.3.3-3 | 4.3.3-3 |
| linux | linux_kernel | >= 0 < 4.3.3-3 | 4.3.3-3 |
| linux | linux_kernel | >= 0 < 3.13.0-79.123 | 3.13.0-79.123 |
CVSS provenance
nvdv3.04.0MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv5.5MEDIUM
vendor_ubuntu5.5MEDIUM
vendor_debian4.0MEDIUM
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (Vivid HWE) regression
vendor_ubuntu·2016-02-27·CVSS 5.5
[MEDIUM] Linux kernel (Vivid HWE) regression
Title: Linux kernel (Vivid HWE) regression
Summary: USN-2910-1 introduced a regression in the Ubuntu 15.04 Linux kernel
backported to Ubuntu 14.04 LTS.
USN-2910-1 fixed vulnerabilities in the Ubuntu 15.04 Linux kernel
backported to Ubuntu 14.04 LTS. An incorrect locking fix caused a
regression that broke graphics displays for Ubuntu 14.04 LTS guests
running the Ubuntu 15.04 backport kernel within VMWare virtual
machines. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
halfdog discovered that OverlayFS, when mounting on top of a FUSE mount,
incorrectly propagated file attributes, including setuid. A local
unprivileged attacker could use this to gain privileges. (CVE-2016-1576)
halfdog discovered that OverlayFS in the Linux kernel incorrect
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2016-02-22·CVSS 5.5
CVE-2015-7550 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
halfdog discovered that OverlayFS, when mounting on top of a FUSE mount,
incorrectly propagated file attributes, including setuid. A local
unprivileged attacker could use this to gain privileges. (CVE-2016-1576)
halfdog discovered that OverlayFS in the Linux kernel incorrectly
propagated security sensitive extended attributes, such as
POSIX ACLs. A local unprivileged attacker could use this to gain
privileges. (CVE-2016-1575)
It was discovered that the Linux kernel keyring subsystem contained a race
between read and revoke operations. A local attacker could use this to
cause a denial of service (system crash). (CVE-2015-7550)
郭永刚 discovered that the Linux kernel networking implementation did
Ubuntu
Linux kernel (Vivid HWE) vulnerabilities
vendor_ubuntu·2016-02-22·CVSS 5.5
CVE-2015-7550 [MEDIUM] Linux kernel (Vivid HWE) vulnerabilities
Title: Linux kernel (Vivid HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
halfdog discovered that OverlayFS, when mounting on top of a FUSE mount,
incorrectly propagated file attributes, including setuid. A local
unprivileged attacker could use this to gain privileges. (CVE-2016-1576)
halfdog discovered that OverlayFS in the Linux kernel incorrectly
propagated security sensitive extended attributes, such as POSIX ACLs. A
local unprivileged attacker could use this to gain privileges.
(CVE-2016-1575)
It was discovered that the Linux kernel keyring subsystem contained a race
between read and revoke operations. A local attacker could use this to
cause a denial of service (system crash). (CVE-2015-7550)
郭永刚 discovered that the Linux kernel networking implem
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2016-02-22·CVSS 5.5
CVE-2015-7550 [MEDIUM] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
halfdog discovered that OverlayFS, when mounting on top of a FUSE mount,
incorrectly propagated file attributes, including setuid. A local
unprivileged attacker could use this to gain privileges. (CVE-2016-1576)
halfdog discovered that OverlayFS in the Linux kernel incorrectly
propagated security sensitive extended attributes, such as
POSIX ACLs. A local unprivileged attacker could use this to gain
privileges. (CVE-2016-1575)
It was discovered that the Linux kernel keyring subsystem contained a race
between read and revoke operations. A local attacker could use this to
cause a denial of service (system crash). (CVE-2015-7550)
郭永刚 discovered that the Linux kernel networking imple
Ubuntu
Linux kernel (Wily HWE) vulnerabilities
vendor_ubuntu·2016-02-02·CVSS 5.3
CVE-2013-7446 [MEDIUM] Linux kernel (Wily HWE) vulnerabilities
Title: Linux kernel (Wily HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that a use-after-free vulnerability existed in the
AF_UNIX implementation in the Linux kernel. A local attacker could use
crafted epoll_ctl calls to cause a denial of service (system crash) or
expose sensitive information. (CVE-2013-7446)
It was discovered that the KVM implementation in the Linux kernel did not
properly restore the values of the Programmable Interrupt Timer (PIT). A
user-assisted attacker in a KVM guest could cause a denial of service in
the host (system crash). (CVE-2015-7513)
It was discovered that the Linux kernel keyring subsystem contained a race
between read and revoke operations. A local attacker could use this to
cause a denial of service
Ubuntu
Linux kernel (Utopic HWE) vulnerabilities
vendor_ubuntu·2016-02-02·CVSS 5.3
CVE-2013-7446 [MEDIUM] Linux kernel (Utopic HWE) vulnerabilities
Title: Linux kernel (Utopic HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that a use-after-free vulnerability existed in the
AF_UNIX implementation in the Linux kernel. A local attacker could use
crafted epoll_ctl calls to cause a denial of service (system crash) or
expose sensitive information. (CVE-2013-7446)
It was discovered that the KVM implementation in the Linux kernel did not
properly restore the values of the Programmable Interrupt Timer (PIT). A
user-assisted attacker in a KVM guest could cause a denial of service in
the host (system crash). (CVE-2015-7513)
It was discovered that the Linux kernel keyring subsystem contained a race
between read and revoke operations. A local attacker could use this to
cause a denial of servic
Ubuntu
Linux kernel (Raspberry Pi 2) vulnerabilities
vendor_ubuntu·2016-02-02·CVSS 5.3
CVE-2013-7446 [MEDIUM] Linux kernel (Raspberry Pi 2) vulnerabilities
Title: Linux kernel (Raspberry Pi 2) vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that a use-after-free vulnerability existed in the
AF_UNIX implementation in the Linux kernel. A local attacker could use
crafted epoll_ctl calls to cause a denial of service (system crash) or
expose sensitive information. (CVE-2013-7446)
It was discovered that the KVM implementation in the Linux kernel did not
properly restore the values of the Programmable Interrupt Timer (PIT). A
user-assisted attacker in a KVM guest could cause a denial of service in
the host (system crash). (CVE-2015-7513)
It was discovered that the Linux kernel keyring subsystem contained a race
between read and revoke operations. A local attacker could use this to
cause a denial of se
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2016-02-02·CVSS 5.3
CVE-2013-7446 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that a use-after-free vulnerability existed in the
AF_UNIX implementation in the Linux kernel. A local attacker could use
crafted epoll_ctl calls to cause a denial of service (system crash) or
expose sensitive information. (CVE-2013-7446)
It was discovered that the KVM implementation in the Linux kernel did not
properly restore the values of the Programmable Interrupt Timer (PIT). A
user-assisted attacker in a KVM guest could cause a denial of service in
the host (system crash). (CVE-2015-7513)
It was discovered that the Linux kernel keyring subsystem contained a race
between read and revoke operations. A local attacker could use this to
cause a denial of service (system cra
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2016-02-01·CVSS 5.3
CVE-2013-7446 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that a use-after-free vulnerability existed in the
AF_UNIX implementation in the Linux kernel. A local attacker could use
crafted epoll_ctl calls to cause a denial of service (system crash) or
expose sensitive information. (CVE-2013-7446)
It was discovered that the KVM implementation in the Linux kernel did not
properly restore the values of the Programmable Interrupt Timer (PIT). A
user-assisted attacker in a KVM guest could cause a denial of service in
the host (system crash). (CVE-2015-7513)
郭永刚 discovered that the ppp implementation in the Linux kernel did
not ensure that certain slot numbers are valid. A local attacker with the
privilege to call ioctl() on /dev/ppp coul
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2016-02-01·CVSS 5.3
CVE-2013-7446 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that a use-after-free vulnerability existed in the
AF_UNIX implementation in the Linux kernel. A local attacker could use
crafted epoll_ctl calls to cause a denial of service (system crash) or
expose sensitive information. (CVE-2013-7446)
It was discovered that the KVM implementation in the Linux kernel did not
properly restore the values of the Programmable Interrupt Timer (PIT). A
user-assisted attacker in a KVM guest could cause a denial of service in
the host (system crash). (CVE-2015-7513)
郭永刚 discovered that the ppp implementation in the Linux kernel did
not ensure that certain slot numbers are valid. A local attacker with the
privilege to call ioctl() on /dev/
Red Hat
kernel: information leak in sco_sock_bind()
vendor_redhat·2015-12-16·CVSS 4.0
CVE-2015-8575 [MEDIUM] CWE-125 kernel: information leak in sco_sock_bind()
kernel: information leak in sco_sock_bind()
The sco_sock_bind function in net/bluetooth/sco.c in the Linux kernel before 4.3.4 does not verify an address length, which allows local users to obtain sensitive information from kernel memory and bypass the KASLR protection mechanism via a crafted application.
An out-of-bounds flaw was found in the kernel, where the sco_sock_bind() function (bluetooth/sco) did not check the length of its sockaddr parameter. As a result, more kernel memory was copied out than required, leaking information from the kernel stack (including kernel addresses). A local user could exploit this flaw to bypass kernel ASLR or leak other information.
Statement: This issue affects the Linux kernel packages as shipped with Red Hat Enterprise Linux 5, 6, 7 and MRG-2. This
Debian
CVE-2015-8575: linux - The sco_sock_bind function in net/bluetooth/sco.c in the Linux kernel before 4.3...
vendor_debian·2015·CVSS 4.0
CVE-2015-8575 [MEDIUM] CVE-2015-8575: linux - The sco_sock_bind function in net/bluetooth/sco.c in the Linux kernel before 4.3...
The sco_sock_bind function in net/bluetooth/sco.c in the Linux kernel before 4.3.4 does not verify an address length, which allows local users to obtain sensitive information from kernel memory and bypass the KASLR protection mechanism via a crafted application.
Scope: local
bookworm: resolved (fixed in 4.3.3-3)
bullseye: resolved (fixed in 4.3.3-3)
forky: resolved (fixed in 4.3.3-3)
sid: resolved (fixed in 4.3.3-3)
trixie: resolved (fixed in 4.3.3-3)
GHSA
GHSA-9939-9cr7-3mvj: The sco_sock_bind function in net/bluetooth/sco
ghsa_unreviewed·2022-05-17
CVE-2015-8575 [MEDIUM] CWE-200 GHSA-9939-9cr7-3mvj: The sco_sock_bind function in net/bluetooth/sco
The sco_sock_bind function in net/bluetooth/sco.c in the Linux kernel before 4.3.4 does not verify an address length, which allows local users to obtain sensitive information from kernel memory and bypass the KASLR protection mechanism via a crafted application.
OSV
linux-lts-vivid regression
osv·2016-02-27·CVSS 5.5
[MEDIUM] linux-lts-vivid regression
linux-lts-vivid regression
USN-2910-1 fixed vulnerabilities in the Ubuntu 15.04 Linux kernel
backported to Ubuntu 14.04 LTS. An incorrect locking fix caused a
regression that broke graphics displays for Ubuntu 14.04 LTS guests
running the Ubuntu 15.04 backport kernel within VMWare virtual
machines. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
halfdog discovered that OverlayFS, when mounting on top of a FUSE mount,
incorrectly propagated file attributes, including setuid. A local
unprivileged attacker could use this to gain privileges. (CVE-2016-1576)
halfdog discovered that OverlayFS in the Linux kernel incorrectly
propagated security sensitive extended attributes, such as POSIX ACLs. A
local unprivileged attacker could use this to gain
OSV
linux-lts-vivid vulnerabilities
osv·2016-02-22·CVSS 5.5
CVE-2016-1576 [MEDIUM] linux-lts-vivid vulnerabilities
linux-lts-vivid vulnerabilities
halfdog discovered that OverlayFS, when mounting on top of a FUSE mount,
incorrectly propagated file attributes, including setuid. A local
unprivileged attacker could use this to gain privileges. (CVE-2016-1576)
halfdog discovered that OverlayFS in the Linux kernel incorrectly
propagated security sensitive extended attributes, such as POSIX ACLs. A
local unprivileged attacker could use this to gain privileges.
(CVE-2016-1575)
It was discovered that the Linux kernel keyring subsystem contained a race
between read and revoke operations. A local attacker could use this to
cause a denial of service (system crash). (CVE-2015-7550)
郭永刚 discovered that the Linux kernel networking implementation did
not validate protocol identifiers for certain protocol families
OSV
linux vulnerabilities
osv·2016-02-22·CVSS 5.5
CVE-2016-1576 [MEDIUM] linux vulnerabilities
linux vulnerabilities
halfdog discovered that OverlayFS, when mounting on top of a FUSE mount,
incorrectly propagated file attributes, including setuid. A local
unprivileged attacker could use this to gain privileges. (CVE-2016-1576)
halfdog discovered that OverlayFS in the Linux kernel incorrectly
propagated security sensitive extended attributes, such as
POSIX ACLs. A local unprivileged attacker could use this to gain
privileges. (CVE-2016-1575)
It was discovered that the Linux kernel keyring subsystem contained a race
between read and revoke operations. A local attacker could use this to
cause a denial of service (system crash). (CVE-2015-7550)
郭永刚 discovered that the Linux kernel networking implementation did
not validate protocol identifiers for certain protocol families, A local
OSV
CVE-2015-8575: The sco_sock_bind function in net/bluetooth/sco
osv·2016-02-08·CVSS 4.0
CVE-2015-8575 [MEDIUM] CVE-2015-8575: The sco_sock_bind function in net/bluetooth/sco
The sco_sock_bind function in net/bluetooth/sco.c in the Linux kernel before 4.3.4 does not verify an address length, which allows local users to obtain sensitive information from kernel memory and bypass the KASLR protection mechanism via a crafted application.
OSV
linux-lts-wily vulnerabilities
osv·2016-02-02·CVSS 5.3
CVE-2013-7446 [MEDIUM] linux-lts-wily vulnerabilities
linux-lts-wily vulnerabilities
It was discovered that a use-after-free vulnerability existed in the
AF_UNIX implementation in the Linux kernel. A local attacker could use
crafted epoll_ctl calls to cause a denial of service (system crash) or
expose sensitive information. (CVE-2013-7446)
It was discovered that the KVM implementation in the Linux kernel did not
properly restore the values of the Programmable Interrupt Timer (PIT). A
user-assisted attacker in a KVM guest could cause a denial of service in
the host (system crash). (CVE-2015-7513)
It was discovered that the Linux kernel keyring subsystem contained a race
between read and revoke operations. A local attacker could use this to
cause a denial of service (system crash). (CVE-2015-7550)
Sasha Levin discovered that the Reliable Da
OSV
linux-lts-utopic vulnerabilities
osv·2016-02-02·CVSS 5.3
CVE-2013-7446 [MEDIUM] linux-lts-utopic vulnerabilities
linux-lts-utopic vulnerabilities
It was discovered that a use-after-free vulnerability existed in the
AF_UNIX implementation in the Linux kernel. A local attacker could use
crafted epoll_ctl calls to cause a denial of service (system crash) or
expose sensitive information. (CVE-2013-7446)
It was discovered that the KVM implementation in the Linux kernel did not
properly restore the values of the Programmable Interrupt Timer (PIT). A
user-assisted attacker in a KVM guest could cause a denial of service in
the host (system crash). (CVE-2015-7513)
It was discovered that the Linux kernel keyring subsystem contained a race
between read and revoke operations. A local attacker could use this to
cause a denial of service (system crash). (CVE-2015-7550)
Sasha Levin discovered that the Reliable
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-8575 kernel: information leak in sco_sock_bind()
bugzilla·2015-12-18·CVSS 2.3
CVE-2015-8575 [LOW] CVE-2015-8575 kernel: information leak in sco_sock_bind()
CVE-2015-8575 kernel: information leak in sco_sock_bind()
An issue similar to CVE-2015-8569 was fixed in the Linux kernel. The sco_sock_bind() function (bluetooth/sco) did not check the length of the passed sockaddr, copying out more kernel memory than required, leaking information from the kernel stack, including kernel addresses. This can be used for KASLR bypass or other information leaks.
Upstream commit:
http://git.kernel.org/cgit/linux/kernel/git/davem/net.git/commit/?id=5233252fce714053f0151680933571a2da9cbfb4
CVE request and assignment:
http://seclists.org/oss-sec/2015/q4/516
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1292841]
---
kernel-4.3.3-300.fc23 has been pushed to the Fedora 23 stable repository. If problems still persist, ple
Bugzilla
CVE-2015-8575 kernel: information leak in sco_sock_bind() [fedora-all]
bugzilla·2015-12-18·CVSS 4.0
CVE-2015-8575 [MEDIUM] CVE-2015-8575 kernel: information leak in sco_sock_bind() [fedora-all]
CVE-2015-8575 kernel: information leak in sco_sock_bind() [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora.
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=5233252fce714053f0151680933571a2da9cbfb4http://lists.fedoraproject.org/pipermail/package-announce/2016-February/176484.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00094.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00045.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00038.htmlhttp://www.debian.org/security/2016/dsa-3434http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.3.4http://www.openwall.com/lists/oss-security/2015/12/16/3http://www.securityfocus.com/bid/79724http://www.ubuntu.com/usn/USN-2886-1http://www.ubuntu.com/usn/USN-2888-1http://www.ubuntu.com/usn/USN-2890-1http://www.ubuntu.com/usn/USN-2890-2http://www.ubuntu.com/usn/USN-2890-3https://bugzilla.redhat.com/show_bug.cgi?id=1292840https://github.com/torvalds/linux/commit/5233252fce714053f0151680933571a2da9cbfb4http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=5233252fce714053f0151680933571a2da9cbfb4http://lists.fedoraproject.org/pipermail/package-announce/2016-February/176484.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00094.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00045.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00038.htmlhttp://www.debian.org/security/2016/dsa-3434http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.3.4http://www.openwall.com/lists/oss-security/2015/12/16/3http://www.securityfocus.com/bid/79724http://www.ubuntu.com/usn/USN-2886-1http://www.ubuntu.com/usn/USN-2888-1http://www.ubuntu.com/usn/USN-2890-1http://www.ubuntu.com/usn/USN-2890-2http://www.ubuntu.com/usn/USN-2890-3https://bugzilla.redhat.com/show_bug.cgi?id=1292840https://github.com/torvalds/linux/commit/5233252fce714053f0151680933571a2da9cbfb4
2016-02-08
Published