CVE-2015-7990 PUBLISHED

Race condition in the rds_sendmsg function in net/rds/sendmsg.c in the Linux kernel before 4.3.3 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by using a socket that was not properly bound. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-6937.

EPSS 0.04% · 13.2th percentile

Risk Scores

EPSS Score
0.04%
13.2th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSlinux-lts-vivid3.19.0-47.53~14.04.1, 3.19.0-43.49~14.04.1, 3.19.0-42.48~14.04.1
Ubuntu:14.04:LTSlinux3.13.0-8.28, 3.13.0-10.30, 3.13.0-11.31
Ubuntu:14.04:LTSlinux-lts-wily0, 4.2.0-18.22~14.04.1, 4.2.0-19.23~14.04.1
Ubuntu:14.04:LTSlinux-lts-utopic3.16.0-50.67~14.04.1, 3.16.0-51.69~14.04.1, 3.16.0-52.71~14.04.1

Timeline

References

Open in Interactive Console →