UBUNTU-CVE-2015-8812
drivers/infiniband/hw/cxgb3/iwch_cm.c in the Linux kernel before 4.5 does not properly identify error conditions, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via crafted packets.
02 / AFFECTED SOFTWARE
Affected packages
87 explicit affected versions
38 explicit affected versions
23 explicit affected versions
10 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
drivers/infiniband/hw/cxgb3/iwch_cm.c in the Linux kernel before 4.5 does not properly identify error conditions, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via crafted packets.
05 / REFERENCES
Further evidence
- http://www.openwall.com/lists/oss-security/2016/02/11/1
- https://bugzilla.redhat.com/show_bug.cgi?id=1303532
- https://ubuntu.com/security/CVE-2015-8812
- https://ubuntu.com/security/notices/USN-2946-1
- https://ubuntu.com/security/notices/USN-2946-2
- https://ubuntu.com/security/notices/USN-2947-1
- https://ubuntu.com/security/notices/USN-2947-2
- https://ubuntu.com/security/notices/USN-2947-3
- https://ubuntu.com/security/notices/USN-2948-1
- https://ubuntu.com/security/notices/USN-2949-1
- https://ubuntu.com/security/notices/USN-2967-1
- https://ubuntu.com/security/notices/USN-2967-2
- https://www.cve.org/CVERecord?id=CVE-2015-8812