CVE-2015-8845

Severity
5.5MEDIUM
EPSS
0.1%
top 80.79%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 27
Latest updateMay 14

Description

The tm_reclaim_thread function in arch/powerpc/kernel/process.c in the Linux kernel before 4.4.1 on powerpc platforms does not ensure that TM suspend mode exists before proceeding with a tm_reclaim call, which allows local users to cause a denial of service (TM Bad Thing exception and panic) via a crafted application.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages9 packages

Patches

🔴Vulnerability Details

3
GHSA
GHSA-6x8f-5gpm-pv5f: The tm_reclaim_thread function in arch/powerpc/kernel/process2022-05-14
OSV
CVE-2015-8845: The tm_reclaim_thread function in arch/powerpc/kernel/process2016-04-27
CVEList
CVE-2015-8845: The tm_reclaim_thread function in arch/powerpc/kernel/process2016-04-27

📋Vendor Advisories

2
Red Hat
kernel: incorrect restoration of machine specific registers from userspace2016-04-13
Debian
CVE-2015-8845: linux - The tm_reclaim_thread function in arch/powerpc/kernel/process.c in the Linux ker...2015

💬Community

2
Bugzilla
CVE-2015-8844 CVE-2015-8845 kernel: incorrect restoration of machine specific registers from userspace [fedora-all]2016-04-13
Bugzilla
CVE-2015-8845 CVE-2015-8844 kernel: incorrect restoration of machine specific registers from userspace2016-04-13