Back

HIGH

kernel: sys_sendto/sys_recvfrom does not validate the user provided ubuf pointer

Published May 2, 2016

Description

net/socket.c in the Linux kernel 3.19 before 3.19.3 does not validate certain range data for (1) sendto and (2) recvfrom system calls, which allows local users to gain privileges by leveraging a subsystem that uses the copy_from_iter function in the iov_iter interface, as demonstrated by the Bluetooth subsystem.

Affected products

Remediation

Red Hat statement

Not vulnerable. This issue does not affect the Linux kernel packages as shipped with Red Hat Entereprise Linux 5, 6, 7 and Red Hat Enterprise MRG 2.

Metrics

Weaknesses (1)

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 2, 2016
Updated Aug 6, 2024
Reserved Mar 23, 2015
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Mar 20, 2015