CVE-2015-5157
arch/x86/entry/entry_64.S in the Linux kernel before 4.1.6 on the x86_64 platform mishandles IRET faults in processing NMIs that occurred during userspace execution, which might allow local users to gain privileges by triggering an NMI.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.62%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
arch/x86/entry/entry_64.S in the Linux kernel before 4.1.6 on the x86_64 platform mishandles IRET faults in processing NMIs that occurred during userspace execution, which might allow local users to gain privileges by triggering an NMI.
- CVSS 2.0
- 7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 0.62% probability · 48th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- redhat/enterprise linux desktop · redhat/enterprise linux hpc node · redhat/enterprise linux server · redhat/enterprise linux server eus · redhat/enterprise linux workstation · linux/linux kernel
- Source
- secalert@redhat.com
References
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=9b6e6a8334d56354853f9c255d1395c2ba570e0aMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-10/msg00009.htmlThird Party Advisory, VDB Entry
- http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00035.htmlThird Party Advisory, VDB Entry
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00026.htmlThird Party Advisory, VDB Entry
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00031.htmlThird Party Advisory, VDB Entry
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00013.htmlThird Party Advisory, VDB Entry
- http://rhn.redhat.com/errata/RHSA-2016-0185.htmlThird Party Advisory, VDB Entry
- http://rhn.redhat.com/errata/RHSA-2016-0212.htmlThird Party Advisory, VDB Entry
- http://rhn.redhat.com/errata/RHSA-2016-0224.htmlThird Party Advisory, VDB Entry
- http://rhn.redhat.com/errata/RHSA-2016-0715.htmlThird Party Advisory, VDB Entry
- http://www.debian.org/security/2015/dsa-3313Third Party Advisory, VDB Entry
- http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.1.6Vendor Advisory
- http://www.openwall.com/lists/oss-security/2015/07/22/7Mailing List
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlThird Party Advisory
- http://www.securityfocus.com/bid/76005Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-2687-1Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-2688-1Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-2689-1Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-2690-1Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-2691-1Third Party Advisory, VDB Entry
- https://github.com/torvalds/linux/commit/9b6e6a8334d56354853f9c255d1395c2ba570e0aThird Party Advisory
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=9b6e6a8334d56354853f9c255d1395c2ba570e0aMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-10/msg00009.htmlThird Party Advisory, VDB Entry
- http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00035.htmlThird Party Advisory, VDB Entry
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00026.htmlThird Party Advisory, VDB Entry
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00031.htmlThird Party Advisory, VDB Entry
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00013.htmlThird Party Advisory, VDB Entry
- http://rhn.redhat.com/errata/RHSA-2016-0185.htmlThird Party Advisory, VDB Entry
- http://rhn.redhat.com/errata/RHSA-2016-0212.htmlThird Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.