CVE-2015-6937

Severity

49%

Complexity

39%

Confidentiality

115%

CWE-476: NULL Pointer Dereference

The __rds_conn_create function in net/rds/connection.c in the Linux kernel through 4.2.3 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by using a socket that was not properly bound.

CWE-476: NULL Pointer Dereference

CVSS 2.0 Base Score 4.9. CVSS Attack Vector: local. CVSS Attack Complexity: low. CVSS Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:C).

Overview

Type

Linux

First reported 9 years ago

2015-10-19 10:59:00

Last updated 6 years ago

2018-10-17 01:29:00

Affected Software

Linux Kernel

Canonical Ubuntu Linux 12.04 LTS

12.04

Canonical Ubuntu Linux 14.04 LTS (Long-Term Support)

14.04

Debian Linux 7.0

7.0

Debian Linux 8.0 (Jessie)

8.0

References

http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=74e98eb085889b0d2d4908f59f6e00026063014f

Patch, Vendor Advisory

FEDORA-2015-16440

Third Party Advisory

FEDORA-2015-16441

Third Party Advisory

FEDORA-2015-16417

Third Party Advisory

SUSE-SU-2015:1727

Mailing List, Third Party Advisory

SUSE-SU-2015:2108

Mailing List, Third Party Advisory

SUSE-SU-2015:2339

Mailing List, Third Party Advisory

SUSE-SU-2015:2350

Mailing List, Third Party Advisory

SUSE-SU-2016:0335

Mailing List, Third Party Advisory

SUSE-SU-2016:0337

Mailing List, Third Party Advisory

SUSE-SU-2016:0354

Mailing List, Third Party Advisory

SUSE-SU-2016:0380

Mailing List, Third Party Advisory

SUSE-SU-2016:0381

Mailing List, Third Party Advisory

SUSE-SU-2016:0383

Mailing List, Third Party Advisory

SUSE-SU-2016:0384

Mailing List, Third Party Advisory

SUSE-SU-2016:0386

Mailing List, Third Party Advisory

SUSE-SU-2016:0387

Mailing List, Third Party Advisory

SUSE-SU-2016:0434

Mailing List, Third Party Advisory

SUSE-SU-2016:2074

Mailing List, Third Party Advisory

openSUSE-SU-2015:2232

Mailing List, Third Party Advisory

DSA-3364

Third Party Advisory

[oss-security] 20150914 CVE-2015-6937 - Linux kernel - NULL pointer dereference in net/rds/connection.c

Mailing List, Third Party Advisory

http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html

http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html

Third Party Advisory

76767

Third Party Advisory, VDB Entry

1034453

Third Party Advisory, VDB Entry

USN-2773-1

Third Party Advisory

USN-2774-1

Third Party Advisory

USN-2777-1

Third Party Advisory

https://bugzilla.redhat.com/show_bug.cgi?id=1263139

Issue Tracking, Third Party Advisory

https://github.com/torvalds/linux/commit/74e98eb085889b0d2d4908f59f6e00026063014f

Patch, Third Party Advisory

Stay updated

ExploitPedia is constantly evolving. Sign up to receive a notification when we release additional functionality.

Get in touch

If you'd like to report a bug or have any suggestions for improvements then please do get in touch with us using this form. We will get back to you as soon as we can.