UBUNTU-CVE-2015-1420
Dashboard / Vulnerabilities / UBUNTU-CVE-2015-1420
UBUNTU-CVE-2015-1420
Summary:
Details: Race condition in the handle_to_path function in fs/fhandle.c in the Linux kernel through 3.19.1 allows local users to bypass intended size restrictions and trigger read operations on additional memory locations by changing the handle_bytes value of a file handle during the execution of this function.
References: https://ubuntu.com/security/CVE-2015-1420, http://marc.info/?l=linux-kernel&m=142247707318982&w=2, https://ubuntu.com/security/notices/USN-2660-1, https://ubuntu.com/security/notices/USN-2661-1, https://ubuntu.com/security/notices/USN-2662-1, https://ubuntu.com/security/notices/USN-2663-1, https://ubuntu.com/security/notices/USN-2664-1, https://ubuntu.com/security/notices/USN-2665-1, https://ubuntu.com/security/notices/USN-2666-1, https://ubuntu.com/security/notices/USN-2667-1, https://www.cve.org/CVERecord?id=CVE-2015-1420
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
