CVE-2015-8830 PUBLISHED

Integer overflow in the aio_setup_single_vector function in fs/aio.c in the Linux kernel 4.0 allows local users to cause a denial of service or possibly have unspecified other impact via a large AIO iovec. NOTE: this vulnerability exists because of a CVE-2012-6701 regression.

EPSS 0.06% · 17.9th percentile

Risk Scores

EPSS Score
0.06%
17.9th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSlinux3.13.0-27.50, 3.11.0-12.19, 3.12.0-1.3
Ubuntu:14.04:LTSlinux-lts-vivid0, 3.19.0-18.18~14.04.1, 3.19.0-20.20~14.04.1
Ubuntu:14.04:LTSlinux-lts-utopic3.16.0-49.65~14.04.1, 3.16.0-50.66~14.04.1, 3.16.0-50.67~14.04.1

Timeline

References

Open in Interactive Console →