CVE-2015-5364

NameCVE-2015-5364
DescriptionThe (1) udp_recvmsg and (2) udpv6_recvmsg functions in the Linux kernel before 4.0.6 do not properly consider yielding a processor, which allows remote attackers to cause a denial of service (system hang) via incorrect checksums within a UDP packet flood.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)
ReferencesDLA-310-1, DSA-3313-1
NVD severityhigh (attack range: remote)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
linux (PTS)wheezy3.2.78-1fixed
wheezy (security)3.2.93-1fixed
jessie3.16.43-2+deb8u2fixed
jessie (security)3.16.43-2+deb8u5fixed
stretch4.9.51-1fixed
stretch (security)4.9.30-2+deb9u5fixed
buster, sid4.13.4-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
linuxsource(unstable)4.0.7-1high
linuxsourcejessie3.16.7-ckt11-1+deb8u2highDSA-3313-1
linuxsourcewheezy3.2.68-1+deb7u3high
linux-2.6source(unstable)(unfixed)high
linux-2.6sourcesqueeze2.6.32-48squeeze14highDLA-310-1

Notes

https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=beb39db59d14990e401e235faf66a6b9b31240b0 (v4.1-rc7)
http://web.archive.org/web/20160309082241/https://twitter.com/grsecurity/status/605854034260426753
http://www.openwall.com/lists/oss-security/2015/06/30/13

Search for package or bug name: Reporting problems