CVE-2015-4004
Not scored
CVE-2015-4004
The OZWPAN driver in the Linux kernel through 4.0.5 relies on an untrusted length field during packet parsing, which allows remote attackers to obtain sensitive information from kernel memory or cause a denial of service (out-of-bounds read and system crash) via a crafted packet.
Exploit probability
8.1%
Published
June 7, 2015
Required by
Not available
Last source change
April 10, 2026
04 / EVIDENCE
Source records
Open Source Vulnerabilities
CVE-2015-4004
View original source
The OZWPAN driver in the Linux kernel through 4.0.5 relies on an untrusted length field during packet parsing, which allows remote attackers to obtain sensitive information from kernel memory or cause a denial of service (out-of-bounds read and system crash) via a crafted packet.
05 / REFERENCES
Further evidence
- http://openwall.com/lists/oss-security/2015/06/05/7
- http://www.securityfocus.com/bid/74669
- http://www.ubuntu.com/usn/USN-2989-1
- http://www.ubuntu.com/usn/USN-2998-1
- http://www.ubuntu.com/usn/USN-3000-1
- http://www.ubuntu.com/usn/USN-3001-1
- http://www.ubuntu.com/usn/USN-3002-1
- http://www.ubuntu.com/usn/USN-3003-1
- http://www.ubuntu.com/usn/USN-3004-1
- https://lkml.org/lkml/2015/5/13/739