UBUNTU-CVE-2015-8830
Integer overflow in the aio_setup_single_vector function in fs/aio.c in the Linux kernel 4.0 allows local users to cause a denial of service or possibly have unspecified other impact via a large AIO iovec. NOTE: this vulnerability exists because of a CVE-2012-6701 regression.
02 / AFFECTED SOFTWARE
Affected packages
88 explicit affected versions
40 explicit affected versions
24 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Integer overflow in the aio_setup_single_vector function in fs/aio.c in the Linux kernel 4.0 allows local users to cause a denial of service or possibly have unspecified other impact via a large AIO iovec. NOTE: this vulnerability exists because of a CVE-2012-6701 regression.
05 / REFERENCES
Further evidence
- http://seclists.org/oss-sec/2016/q1/491
- https://git.kernel.org/linus/4c185ce06dca14f5cea192f5a2c981ef50663f2b
- https://ubuntu.com/security/CVE-2015-8830
- https://ubuntu.com/security/notices/USN-2968-1
- https://ubuntu.com/security/notices/USN-2968-2
- https://ubuntu.com/security/notices/USN-2969-1
- https://ubuntu.com/security/notices/USN-2970-1
- https://www.cve.org/CVERecord?id=CVE-2015-8830