All errata/t7/ALT-PU-2015-1576-1
ALT-PU-2015-1576-1

Package update kernel-image-std-def in branch t7

Version3.14.45-alt1
Published2015-06-27
Max severityCRITICAL
Severity:

Closed issues (3)

CVE-2015-4002
CRITICAL9.0

drivers/staging/ozwpan/ozusbsvc1.c in the OZWPAN driver in the Linux kernel through 4.0.5 does not ensure that certain length values are sufficiently large, which allows remote attackers to cause a denial of service (system crash or large loop) or possibly execute arbitrary code via a crafted packet, related to the (1) oz_usb_rx and (2) oz_usb_handle_ep_data functions.

Published: 2015-06-07Modified: 2025-04-12
CVSS 2.0CRITICAL 9.0
CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:P/A:C
CVE-2015-5364
HIGH7.8

The (1) udp_recvmsg and (2) udpv6_recvmsg functions in the Linux kernel before 4.0.6 do not properly consider yielding a processor, which allows remote attackers to cause a denial of service (system hang) via incorrect checksums within a UDP packet flood.

Published: 2015-08-31Modified: 2025-04-12
CVSS 2.0HIGH 7.8
CVSS:2.0/AV:N/AC:L/Au:N/C:N/I:N/A:C
References