CVE-2015-3331

CVSS v2.0 9.3 (High)
93% Progress
EPSS 0.23 % (62th)
0.23% Progress
Affected Products 3
Advisories 25

The __driver_rfc4106_decrypt function in arch/x86/crypto/aesni-intel_glue.c in the Linux kernel before 3.19.3 does not properly determine the memory locations used for encrypted data, which allows context-dependent attackers to cause a denial of service (buffer overflow and system crash) or possibly execute arbitrary code by triggering a crypto API call, as demonstrated by use of a libkcapi test program with an AF_ALG(aead) socket.

Weaknesses
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
CVE Status
PUBLISHED
CNA
MITRE
Published Date
2015-05-27 10:59:07
(9 years ago)
Updated Date
2023-11-07 02:25:36
(10 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Linux Kernel prior 3.2.69 version cpe:2.3:o:linux:linux_kernel < 3.2.69
  Linux Kernel from 3.3 version and prior 3.4.108 version cpe:2.3:o:linux:linux_kernel >= 3.3 < 3.4.108
  Linux Kernel from 3.5 version and prior 3.10.73 version cpe:2.3:o:linux:linux_kernel >= 3.5 < 3.10.73
  Linux Kernel from 3.12 version and prior 3.12.40 version cpe:2.3:o:linux:linux_kernel >= 3.12 < 3.12.40
  Linux Kernel from 3.13 version and prior 3.14.37 version cpe:2.3:o:linux:linux_kernel >= 3.13 < 3.14.37
  Linux Kernel from 3.15 version and prior 3.16.35 version cpe:2.3:o:linux:linux_kernel >= 3.15 < 3.16.35
  Linux Kernel from 3.17 version and prior 3.18.11 version cpe:2.3:o:linux:linux_kernel >= 3.17 < 3.18.11
  Linux Kernel from 3.19 version and prior 3.19.3 version cpe:2.3:o:linux:linux_kernel >= 3.19 < 3.19.3

Configuration #2

    CPE23 From Up To
  Debian Linux 7.0 cpe:2.3:o:debian:debian_linux:7.0
  Debian Linux 8.0 cpe:2.3:o:debian:debian_linux:8.0

Configuration #3

    CPE23 From Up To
  Canonical Ubuntu Linux 12.04 cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:-
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...