CVE-2015-1420 PUBLISHED

Race condition in the handle_to_path function in fs/fhandle.c in the Linux kernel through 3.19.1 allows local users to bypass intended size restrictions and trigger read operations on additional memory locations by changing the handle_bytes value of a file handle during the execution of this function.

EPSS 0.03% · 7.6th percentile

Risk Scores

EPSS Score
0.03%
7.6th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSlinux-lts-vivid3.19.0-21.21~14.04.1, 3.19.0-20.20~14.04.1, 3.19.0-18.18~14.04.1
Ubuntu:14.04:LTSlinux3.13.0-24.46, 3.13.0-24.47, 3.13.0-27.50
Ubuntu:14.04:LTSlinux-lts-utopic3.16.0-28.38~14.04.1, 3.16.0-29.39~14.04.1, 3.16.0-30.40~14.04.1

Timeline

References

Open in Interactive Console →