CVE-2015-4036

CVSS v2.0 7.2 (High)
72% Progress
EPSS 0.09 % (38th)
0.09% Progress
Affected Products 1
Advisories 7

Array index error in the tcm_vhost_make_tpg function in drivers/vhost/scsi.c in the Linux kernel before 4.0 might allow guest OS users to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted VHOST_SCSI_SET_ENDPOINT ioctl call. NOTE: the affected function was renamed to vhost_scsi_make_tpg before the vulnerability was announced.

Weaknesses
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
CVE Status
PUBLISHED
CNA
MITRE
Published Date
2015-08-31 20:59:01
(9 years ago)
Updated Date
2023-11-21 19:15:17
(10 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Linux Kernel above 3.6 version and prior 3.10.90 version cpe:2.3:o:linux:linux_kernel > 3.6 < 3.10.90
  Linux Kernel from 3.11 version and prior 3.12.44 version cpe:2.3:o:linux:linux_kernel >= 3.11 < 3.12.44
  Linux Kernel from 3.13 version and prior 3.14.57 version cpe:2.3:o:linux:linux_kernel >= 3.13 < 3.14.57
  Linux Kernel from 3.15 version and prior 3.16.35 version cpe:2.3:o:linux:linux_kernel >= 3.15 < 3.16.35
  Linux Kernel from 3.17 version and prior 3.18.25 version cpe:2.3:o:linux:linux_kernel >= 3.17 < 3.18.25
  Linux Kernel from 3.19 version and prior 4.0 version cpe:2.3:o:linux:linux_kernel >= 3.19 < 4.0
  Linux Kernel 3.6 cpe:2.3:o:linux:linux_kernel:3.6:-
  Linux Kernel 3.6 Rc2 cpe:2.3:o:linux:linux_kernel:3.6:rc2
  Linux Kernel 3.6 Rc3 cpe:2.3:o:linux:linux_kernel:3.6:rc3
  Linux Kernel 3.6 Rc4 cpe:2.3:o:linux:linux_kernel:3.6:rc4
  Linux Kernel 3.6 Rc5 cpe:2.3:o:linux:linux_kernel:3.6:rc5
  Linux Kernel 3.6 Rc6 cpe:2.3:o:linux:linux_kernel:3.6:rc6
  Linux Kernel 3.6 Rc7 cpe:2.3:o:linux:linux_kernel:3.6:rc7
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...