Description
Array index error in the tcm_vhost_make_tpg function in drivers/vhost/scsi.c in the Linux kernel before 4.0 might allow guest OS users to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted VHOST_SCSI_SET_ENDPOINT ioctl call. NOTE: the affected function was renamed to vhost_scsi_make_tpg before the vulnerability was announced.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2015-4064 | Array index error in the tcm_vhost_make_tpg function in drivers/vhost/scsi.c in the Linux kernel before 4.0 might allow guest OS users to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted VHOST_SCSI_SET_ENDPOINT ioctl call. NOTE: the affected function was renamed to vhost_scsi_make_tpg before the vulnerability was announced. |
Ubuntu USN |
USN-2564-1 | Linux kernel (Utopic HWE) vulnerabilities |
Ubuntu USN |
USN-2565-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-2633-1 | Linux kernel (Trusty HWE) vulnerabilities |
Ubuntu USN |
USN-2634-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-2636-1 | Linux kernel (Vivid HWE) vulnerabilities |
Ubuntu USN |
USN-2638-1 | Linux kernel vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T06:04:02.583Z
Reserved: 2015-05-19T00:00:00.000Z
Link: CVE-2015-4036
No data.
Status : Modified
Published: 2015-08-31T20:59:01.653
Modified: 2026-05-06T22:30:45.220
Link: CVE-2015-4036
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Ubuntu USN