← Back

CVE-2015-4036

nvd nist
Published: Aug 31, 2015Modified: May 6, 2026

JSON object

Loading...
7.2
Vector
AV:L/AC:L/Au:N/C:C/I:C/A:C
Exploitability: 3.9 / Impact: 10.0
Source: NVD

Description

Array index error in the tcm_vhost_make_tpg function in drivers/vhost/scsi.c in the Linux kernel before 4.0 might allow guest OS users to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted VHOST_SCSI_SET_ENDPOINT ioctl call. NOTE: the affected function was renamed to vhost_scsi_make_tpg before the vulnerability was announced.

Affected (13)

Products: Linux: Linux Kernel
1 product
Linux Kernel
Configuration A
13 vulnerable
Vulnerable SoftwareAffected Versions
Linux
After 3.6 to 3.10.90
From 3.11 to 3.12.44
From 3.13 to 3.14.57
From 3.15 to 3.16.35
From 3.17 to 3.18.25
From 3.19 to 4.0
Version 3.6
Version 3.6 rc2
Version 3.6 rc3
Version 3.6 rc4
Version 3.6 rc5
Version 3.6 rc6
Version 3.6 rc7

References (20)

Source: cve@mitre.org
ExploitMailing ListThird Party Advisory
Source: cve@mitre.org
VDB EntryURL Repurposed
Source: cve@mitre.org
URL Repurposed
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
VDB EntryURL Repurposed
Source: af854a3a-2127-422b-91ae-364da2661108
URL Repurposed
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.