kernel: ping sockets: use-after-free leading to local privilege escalation
Published Aug 6, 2015
4.9
MEDIUMCVSS 2.0
EPSS 2.47%
Description
The ping_unhash function in net/ipv4/ping.c in the Linux kernel before 4.0.3 does not initialize a certain list data structure during an unhash operation, which allows local users to gain privileges or cause a denial of service (use-after-free and system crash) by leveraging the ability to make a SOCK_DGRAM socket system call for the IPPROTO_ICMP or IPPROTO_ICMPV6 protocol, and then making a connect system call after a disconnect.
Affected products
No data.
Configuration 1
- ≤ 4.0.2
Configuration 2
- 7.0
- 6.0
Configuration 3
- 12.04
No data.
Red Hat Enterprise Linux 6
kernel-0:2.6.32-504.30.3.el6
Fixed · RHSA-2015:1221
Red Hat Enterprise Linux 6.4 Advanced Update Support
kernel-0:2.6.32-358.65.1.el6
Fixed · RHSA-2015:1643
Red Hat Enterprise Linux 6.5 Extended Update Support
kernel-0:2.6.32-431.61.2.el6
Fixed · RHSA-2015:1583
Red Hat Enterprise Linux 7
kernel-0:3.10.0-229.11.1.ael7b
Fixed · RHSA-2015:1534
Red Hat Enterprise Linux 7
kernel-rt-0:3.10.0-229.11.1.rt56.141.11.el7_1
Fixed · RHSA-2015:1565
Red Hat Enterprise MRG 2
kernel-rt-1:3.10.0-229.rt56.158.el6rt
Fixed · RHSA-2015:1564
Red Hat Enterprise Linux 5
kernel
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel-0:2.6.32-504.30.3.el6 | Fixed | RHSA-2015:1221 |
| Red Hat Enterprise Linux 6.4 Advanced Update Support | kernel-0:2.6.32-358.65.1.el6 | Fixed | RHSA-2015:1643 |
| Red Hat Enterprise Linux 6.5 Extended Update Support | kernel-0:2.6.32-431.61.2.el6 | Fixed | RHSA-2015:1583 |
| Red Hat Enterprise Linux 7 | kernel-0:3.10.0-229.11.1.ael7b | Fixed | RHSA-2015:1534 |
| Red Hat Enterprise Linux 7 | kernel-rt-0:3.10.0-229.11.1.rt56.141.11.el7_1 | Fixed | RHSA-2015:1565 |
| Red Hat Enterprise MRG 2 | kernel-rt-1:3.10.0-229.rt56.158.el6rt | Fixed | RHSA-2015:1564 |
| Red Hat Enterprise Linux 5 | kernel | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue does not affect the Linux kernel as shipped with Red Hat Enterprise Linux 5. This issue does affect the Linux kernel as shipped with Red Hat Enterprise Linux 6, 7 and Red Hat Enterprise MRG 2. Future kernel updates for the respective releases will address this issue. Please note that on x86-64 architecture systems the impact is limited to local Denial of Service and that the ping sockets functionality is disabled by default (net.ipv4.ping_group_range sysctl is "10").
Red Hat mitigation
You can check whether ping socket functionality is enabled by examining the net.ipv4.ping_group_range sysctl value: ~]# sysctl net.ipv4.ping_group_range net.ipv4.ping_group_range = 10 "1 0" is the default value and disables the ping socket functionality even for root user. Any other value means that the ping socket functionality might be enabled for certain users on the system. To mitigate this vulnerability make sure that you either allow the functionality to trusted local users (groups) only or set the net.ipv4.ping_group_range sysctl to the default and disabled state: ~]# sysctl net.ipv4.ping_group_range="1 0" Please note that this might prevent some programs relying on this functionality from functioning properly.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:L/AC:L/Au:N/C:N/I:N/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (12 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 2.47% (0.02472) | 83.95th | v5 (v2026.06.15) |
| Jun 15, 2026 | 2.47% (0.02472) | 82.39th | v5 (v2026.06.15) |
| Apr 15, 2026 | 3.30% (0.03303) | 87.25th | v4 (v2025.03.14) |
| Feb 28, 2026 | 2.09% (0.02087) | 83.74th | v4 (v2025.03.14) |
| Feb 1, 2026 | 3.26% (0.03264) | 86.88th | v4 (v2025.03.14) |
| Mar 17, 2025 | 2.22% (0.02219) | 83.33th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00044) | 11.89th | v3 (v2023.03.01) |
| Jul 2, 2024 | 0.04% (0.00044) | 10.25th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.04% (0.00044) | 8.24th | v3 (v2023.03.01) |
| Mar 6, 2023 | 5.84% (0.05839) | 90.48th | v2 (v2022.01.01) |
| Apr 1, 2022 | 5.84% (0.05839) | 89.54th | v2 (v2022.01.01) |
| Feb 4, 2022 | 5.84% (0.05839) | 77.39th | v2 (v2022.01.01) |
References (31)
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=a134f083e79fb4c3d0a925691e732c56911b4326 x_refsource_CONFIRM
- http://lists.fedoraproject.org/pipermail/package-announce/2015-May/157788.html vendor-advisoryx_refsource_FEDORA
- http://lists.fedoraproject.org/pipermail/package-announce/2015-May/157897.html vendor-advisoryx_refsource_FEDORA
- http://lists.fedoraproject.org/pipermail/package-announce/2015-May/158804.html vendor-advisoryx_refsource_FEDORA
- http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00023.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00011.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00004.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00007.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00008.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00009.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00011.html vendor-advisoryx_refsource_SUSE
- http://rhn.redhat.com/errata/RHSA-2015-1221.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2015-1534.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2015-1564.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2015-1583.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2015-1643.html vendor-advisoryx_refsource_REDHAT
- http://www.debian.org/security/2015/dsa-3290 vendor-advisoryx_refsource_DEBIAN
- http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.0.3 x_refsource_CONFIRM
- http://www.openwall.com/lists/oss-security/2015/05/02/5 mailing-listx_refsource_MLIST
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html x_refsource_CONFIRM
- http://www.securityfocus.com/bid/74450 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id/1033186 vdb-entryx_refsource_SECTRACK
- http://www.ubuntu.com/usn/USN-2631-1 vendor-advisoryx_refsource_UBUNTU
- http://www.ubuntu.com/usn/USN-2632-1 vendor-advisoryx_refsource_UBUNTU
- http://www.ubuntu.com/usn/USN-2633-1 vendor-advisoryx_refsource_UBUNTU
- http://www.ubuntu.com/usn/USN-2634-1 vendor-advisoryx_refsource_UBUNTU
- https://access.redhat.com/security/cve/CVE-2015-3636 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1218074 x_refsource_CONFIRMIssue Tracking
- https://github.com/torvalds/linux/commit/a134f083e79fb4c3d0a925691e732c56911b4326 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2015-3636
- https://www.cve.org/CVERecord?id=CVE-2015-3636
Change history (0)
No recorded changes yet.