CVE-2015-3332

CVSS v2.0 4.9 (Medium)
49% Progress
EPSS 0.04 % (5th)
0.04% Progress
Affected Products 2
Advisories 5

A certain backport in the TCP Fast Open implementation for the Linux kernel before 3.18 does not properly maintain a count value, which allow local users to cause a denial of service (system crash) via the Fast Open feature, as demonstrated by visiting the chrome://flags/#enable-tcp-fast-open URL when using certain 3.10.x through 3.16.x kernel builds, including longterm-maintenance releases and ckt (aka Canonical Kernel Team) builds.

Weaknesses
CWE-399
Resource Management Errors
CVE Status
PUBLISHED
CNA
MITRE
Published Date
2015-05-27 10:59:08
(9 years ago)
Updated Date
2016-04-11 18:54:08
(8 years ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Debian Linux cpe:2.3:o:debian:debian_linux

Configuration #2

    CPE23 From Up To
  Linux Kernel 3.17.8 and prior versions cpe:2.3:o:linux:linux_kernel <= 3.17.8
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...