CVE-2015-8787
The nf_nat_redirect_ipv4 function in net/netfilter/nf_nat_redirect.c in the Linux kernel before 4.4 allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by sending…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (9.23%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The nf_nat_redirect_ipv4 function in net/netfilter/nf_nat_redirect.c in the Linux kernel before 4.4 allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by sending certain IPv4 packets to an incompletely configured interface, a related issue to CVE-2003-1604.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 9.23% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-476
- Affected
- linux/linux kernel
- Source
- security@debian.org
References
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=94f9cd81436c85d8c3a318ba92e236ede73752fcIssue Tracking, Patch, Vendor Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2016-February/176464.htmlThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2016-February/176484.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00015.htmlThird Party Advisory
- http://www.openwall.com/lists/oss-security/2016/01/27/6Mailing List
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.htmlThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/ovmbulletinoct2016-3090547.htmlThird Party Advisory
- http://www.ubuntu.com/usn/USN-2889-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-2889-2Third Party Advisory
- http://www.ubuntu.com/usn/USN-2890-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-2890-2Third Party Advisory
- http://www.ubuntu.com/usn/USN-2890-3Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1300731Issue Tracking
- https://github.com/torvalds/linux/commit/94f9cd81436c85d8c3a318ba92e236ede73752fcIssue Tracking, Patch, Third Party Advisory
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=94f9cd81436c85d8c3a318ba92e236ede73752fcIssue Tracking, Patch, Vendor Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2016-February/176464.htmlThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2016-February/176484.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00015.htmlThird Party Advisory
- http://www.openwall.com/lists/oss-security/2016/01/27/6Mailing List
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.htmlThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/ovmbulletinoct2016-3090547.htmlThird Party Advisory
- http://www.ubuntu.com/usn/USN-2889-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-2889-2Third Party Advisory
- http://www.ubuntu.com/usn/USN-2890-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-2890-2Third Party Advisory
- http://www.ubuntu.com/usn/USN-2890-3Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1300731Issue Tracking
- https://github.com/torvalds/linux/commit/94f9cd81436c85d8c3a318ba92e236ede73752fcIssue Tracking, Patch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.