CVE-2015-4001 PUBLISHED

Integer signedness error in the oz_hcd_get_desc_cnf function in drivers/staging/ozwpan/ozhcd.c in the OZWPAN driver in the Linux kernel through 4.0.5 allows remote attackers to cause a denial of service (system crash) or possibly execute arbitrary code via a crafted packet.

EPSS 5.91% · 90.5th percentile

Risk Scores

EPSS Score
5.91%
90.5th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSlinux-lts-utopic0, 3.16.0-25.33~14.04.2, 3.16.0-26.35~14.04.1
Ubuntu:14.04:LTSlinux-lts-vivid3.19.0-18.18~14.04.1, 3.19.0-20.20~14.04.1, 3.19.0-21.21~14.04.1
Ubuntu:14.04:LTSlinux3.13.0-19.39, 3.13.0-19.40, 3.13.0-20.42

Timeline

References

Open in Interactive Console →