kernel: pipe: iovec overrun leading to memory corruption
Published Aug 8, 2015
7.2
HIGHCVSS 2.0
EPSS 1.40%
Description
The (1) pipe_read and (2) pipe_write implementations in fs/pipe.c in the Linux kernel before 3.16 do not properly consider the side effects of failed __copy_to_user_inatomic and __copy_from_user_inatomic calls, which allows local users to cause a denial of service (system crash) or possibly gain privileges via a crafted application, aka an "I/O vector array overrun."
Affected products
No data.
No data.
Red Hat Enterprise Linux 5
kernel-0:2.6.18-406.el5
Fixed · RHSA-2015:1042
Red Hat Enterprise Linux 5.6 Long Life
kernel-0:2.6.18-238.56.1.el5
Fixed · RHSA-2015:1190
Red Hat Enterprise Linux 5.9 Long Life
kernel-0:2.6.18-348.31.2.el5
Fixed · RHSA-2015:1120
Red Hat Enterprise Linux 6
kernel-0:2.6.32-504.23.4.el6
Fixed · RHSA-2015:1081
Red Hat Enterprise Linux 6.2 Advanced Update Support
kernel-0:2.6.32-220.63.2.el6
Fixed · RHSA-2015:1082
Red Hat Enterprise Linux 6.4 Advanced Update Support
kernel-0:2.6.32-358.62.1.el6
Fixed · RHSA-2015:1211
Red Hat Enterprise Linux 6.5 Extended Update Support
kernel-0:2.6.32-431.59.1.el6
Fixed · RHSA-2015:1199
Red Hat Enterprise Linux 7
kernel-0:3.10.0-229.7.2.ael7b
Fixed · RHSA-2015:1137
Red Hat Enterprise Linux 7
kernel-rt-0:3.10.0-229.7.2.rt56.141.6.el7_1
Fixed · RHSA-2015:1139
Red Hat Enterprise MRG 2
kernel-rt-1:3.10.0-229.rt56.153.el6rt
Fixed · RHSA-2015:1138
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | kernel-0:2.6.18-406.el5 | Fixed | RHSA-2015:1042 |
| Red Hat Enterprise Linux 5.6 Long Life | kernel-0:2.6.18-238.56.1.el5 | Fixed | RHSA-2015:1190 |
| Red Hat Enterprise Linux 5.9 Long Life | kernel-0:2.6.18-348.31.2.el5 | Fixed | RHSA-2015:1120 |
| Red Hat Enterprise Linux 6 | kernel-0:2.6.32-504.23.4.el6 | Fixed | RHSA-2015:1081 |
| Red Hat Enterprise Linux 6.2 Advanced Update Support | kernel-0:2.6.32-220.63.2.el6 | Fixed | RHSA-2015:1082 |
| Red Hat Enterprise Linux 6.4 Advanced Update Support | kernel-0:2.6.32-358.62.1.el6 | Fixed | RHSA-2015:1211 |
| Red Hat Enterprise Linux 6.5 Extended Update Support | kernel-0:2.6.32-431.59.1.el6 | Fixed | RHSA-2015:1199 |
| Red Hat Enterprise Linux 7 | kernel-0:3.10.0-229.7.2.ael7b | Fixed | RHSA-2015:1137 |
| Red Hat Enterprise Linux 7 | kernel-rt-0:3.10.0-229.7.2.rt56.141.6.el7_1 | Fixed | RHSA-2015:1139 |
| Red Hat Enterprise MRG 2 | kernel-rt-1:3.10.0-229.rt56.153.el6rt | Fixed | RHSA-2015:1138 |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue does affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 5, 6, and 7, and Red Hat Enterprise MRG 2. Future Linux kernel updates for the respective releases will address this issue.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:L/AC:L/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (21 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 1.40% (0.01395) | 71.40th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.48% (0.01478) | 70.43th | v5 (v2026.06.15) |
| May 17, 2026 | 9.01% (0.09009) | 92.70th | v4 (v2025.03.14) |
| Apr 12, 2026 | 14.77% (0.14775) | 94.50th | v4 (v2025.03.14) |
| Mar 24, 2026 | 17.84% (0.17837) | 95.07th | v4 (v2025.03.14) |
| Mar 17, 2026 | 19.61% (0.19605) | 95.34th | v4 (v2025.03.14) |
| Feb 24, 2026 | 16.68% (0.16676) | 94.79th | v4 (v2025.03.14) |
| Oct 2, 2025 | 15.14% (0.15143) | 94.38th | v4 (v2025.03.14) |
| Sep 8, 2025 | 16.66% (0.16663) | 94.67th | v4 (v2025.03.14) |
| Sep 4, 2025 | 14.85% (0.14850) | 94.29th | v4 (v2025.03.14) |
| Apr 28, 2025 | 7.80% (0.07804) | 91.46th | v4 (v2025.03.14) |
| Mar 25, 2025 | 9.49% (0.09490) | 92.02th | v4 (v2025.03.14) |
| Mar 17, 2025 | 8.38% (0.08375) | 91.68th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00044) | 11.89th | v3 (v2023.03.01) |
| Jul 2, 2024 | 0.04% (0.00044) | 10.25th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.04% (0.00044) | 8.24th | v3 (v2023.03.01) |
| Mar 6, 2023 | 6.67% (0.06674) | 91.55th | v2 (v2022.01.01) |
| Feb 13, 2023 | 6.67% (0.06674) | 91.22th | v2 (v2022.01.01) |
| Feb 3, 2023 | 6.79% (0.06793) | 91.85th | v2 (v2022.01.01) |
| Apr 1, 2022 | 6.67% (0.06674) | 90.73th | v2 (v2022.01.01) |
| Feb 4, 2022 | 6.67% (0.06674) | 78.72th | v2 (v2022.01.01) |
References (39)
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=637b58c2887e5e57850865839cc75f59184b23d1 x_refsource_CONFIRM
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=f0d1bec9d58d4c038d0ac958c9af82be6eb18045 x_refsource_CONFIRM
- http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00023.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00049.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00004.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00007.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00008.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00009.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00010.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00011.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00018.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00021.html vendor-advisoryx_refsource_SUSE
- http://rhn.redhat.com/errata/RHSA-2015-1042.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2015-1081.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2015-1082.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2015-1120.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2015-1137.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2015-1138.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2015-1190.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2015-1199.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2015-1211.html vendor-advisoryx_refsource_REDHAT
- http://source.android.com/security/bulletin/2016-04-02.html x_refsource_CONFIRM
- http://source.android.com/security/bulletin/2016-05-01.html x_refsource_CONFIRM
- http://www.debian.org/security/2015/dsa-3290 vendor-advisoryx_refsource_DEBIAN
- http://www.openwall.com/lists/oss-security/2015/06/06/2 mailing-listx_refsource_MLIST
- http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html x_refsource_CONFIRM
- http://www.securityfocus.com/bid/74951 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id/1032454 vdb-entryx_refsource_SECTRACK
- http://www.ubuntu.com/usn/USN-2679-1 vendor-advisoryx_refsource_UBUNTU
- http://www.ubuntu.com/usn/USN-2680-1 vendor-advisoryx_refsource_UBUNTU
- http://www.ubuntu.com/usn/USN-2681-1 vendor-advisoryx_refsource_UBUNTU
- http://www.ubuntu.com/usn/USN-2967-1 vendor-advisoryx_refsource_UBUNTU
- http://www.ubuntu.com/usn/USN-2967-2 vendor-advisoryx_refsource_UBUNTU
- https://access.redhat.com/security/cve/CVE-2015-1805 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1202855 x_refsource_CONFIRMIssue Tracking
- https://github.com/torvalds/linux/commit/637b58c2887e5e57850865839cc75f59184b23d1 x_refsource_CONFIRM
- https://github.com/torvalds/linux/commit/f0d1bec9d58d4c038d0ac958c9af82be6eb18045 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2015-1805
- https://www.cve.org/CVERecord?id=CVE-2015-1805
Change history (0)
No recorded changes yet.