CVE-2015-8019

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
02/05/2016
Last modified:
12/04/2025

Description

The skb_copy_and_csum_datagram_iovec function in net/core/datagram.c in the Linux kernel 3.14.54 and 3.18.22 does not accept a length argument, which allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact via a write system call followed by a recvmsg system call.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:3.14.54:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:3.18.22:*:*:*:*:*:*:*