Linux kernel OZWPAN driver information leakage Vulnerability (CVE-2015-4004)
Linux kernel OZWPAN driver information leakage Vulnerability (CVE-2015-4004)
Release date:
Updated on:
Affected Systems:
Linux kernel <4.0.5
Description:
CVE (CAN) ID: CVE-2015-4004
Linux Kernel is the Kernel of the Linux operating system.
During data parsing in versions earlier than Linux kernel 4.0.5, The OZWPAN driver trusts the suspicious length field, which allows remote attackers to construct packets, attackers can exploit this vulnerability to obtain sensitive information about the kernel memory or cause denial of service (DoS) attacks.
<* Source: anonymous
*>
Suggestion:
Vendor patch:
Linux
-----
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://openwall.com/lists/oss-security/2015/06/05/7
Https://lkml.org/lkml/2015/5/13/739
How to install Kernel 4.0.2 on CentOS 7
How to install Linux Kernel 4.0 on CentOS 7
How to install Linux kernel 4.0 on Ubuntu/CentOS?
How to install Linux kernel 13.10 On Ubuntu 3.12
How to install the 3.16.7 CKT2 kernel in Ubuntu 14.10, Ubuntu 14.04, and its derivative versions
Linux Kernel: click here
Linux Kernel: click here
This article permanently updates the link address: