VDB

CVE-2015-8970

CVE-2015-8970 PUBLISHED

crypto/algif_skcipher.c in the Linux kernel before 4.4.2 does not verify that a setkey operation has been performed on an AF_ALG socket before an accept system call is processed, which allows local users to cause a denial of service (NULL pointer dereference and system crash) via a crafted application that does not supply a key, related to the lrw_crypt function in crypto/lrw.c.

EPSS 0.04% · 11.9th percentile

Risk Scores

EPSS Score
0.04%
11.9th percentile

Affected Products

VendorProductVersions
Ubuntu:22.04:LTSlinux-realtime5.15.0-1032.35, 0
Ubuntu:14.04:LTSlinux-lts-vivid3.19.0-30.34~14.04.1, 3.19.0-31.36~14.04.1, 3.19.0-32.37~14.04.1
Ubuntu:20.04:LTSlinux-raspi25.4.0-1006.6, 5.3.0-1017.19, 5.3.0-1015.17
Ubuntu:22.04:LTSlinux-intel-iot-realtime5.15.0-1073.75, 0
Ubuntu:20.04:LTSlinux-riscv0, 5.4.0-30.34, 5.4.0-26.30
Ubuntu:22.04:LTSlinux-riscv5.13.0-1004.4, 5.15.0-1018.21, 5.15.0-1008.8
Ubuntu:Pro:14.04:LTSlinux3.13.0-196.247, 0, 3.11.0-12.19
Ubuntu:20.04:LTSlinux-azure-fde5.4.0-1092.97+cvm1.1, 5.4.0-1095.101+cvm1.1, 5.4.0-1098.104+cvm1.1
Ubuntu:20.04:LTSlinux-gke5.4.0-1071.76, 5.4.0-1067.70, 5.4.0-1066.69
Ubuntu:20.04:LTSlinux-gkeop5.4.0-1029.30, 5.4.0-1079.83, 5.4.0-1080.84
Ubuntu:24.04:LTSlinux-raspi-realtime6.8.0-2019.20, 0
Ubuntu:20.04:LTSlinux-gkeop-5.15*, *, 5.15.0-1036.42~20.04.1

Timeline

  • Nov 28, 2016 CVE Published
  • Feb 4, 2022 EPSS Score
  • Mar 29, 2022 EPSS Score
  • May 20, 2022 EPSS Score
  • Jul 12, 2022 EPSS Score
  • Sep 3, 2022 EPSS Score
  • Oct 26, 2022 EPSS Score
  • Dec 18, 2022 EPSS Score
  • Feb 8, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 2, 2023 EPSS Score
  • May 25, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›