← Back

CVE-2015-4002

nvd nist
Published: Jun 7, 2015Modified: May 6, 2026

JSON object

Loading...
9.0
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:C
Exploitability: 10.0 / Impact: 8.5
Source: NVD

Description

drivers/staging/ozwpan/ozusbsvc1.c in the OZWPAN driver in the Linux kernel through 4.0.5 does not ensure that certain length values are sufficiently large, which allows remote attackers to cause a denial of service (system crash or large loop) or possibly execute arbitrary code via a crafted packet, related to the (1) oz_usb_rx and (2) oz_usb_handle_ep_data functions.

Affected (10)

1 product
Linux Kernel
1 product
Ubuntu Linux
1 product
Opensuse
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Linux
Before 3.4.109
From 3.11 to 3.12.45
From 3.13 to 3.14.45
From 3.15 to 3.16.35
From 3.17 to 3.18.18
From 3.19 to 4.0.6
From 3.5 to 3.10.81
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Version 14.04
Version 15.10
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 13.2

References (18)

Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.