SB2015032101 - Fedora 21 update for kernel
Published: March 21, 2015 Updated: April 24, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 secuirty vulnerabilities.
1) Memory corruption (CVE-ID: CVE-2015-2666)
The vulnerability allows a local user to execute arbitrary code.
The vulnerability exists due to memory corruption error. A local user can execute arbitrary code.
2) Improper input validation (CVE-ID: CVE-2015-2672)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation error within the arch/x86/include/asm/xsave.h. A local user can perform a denial of service (DoS) attack.
3) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2015-2686)
The vulnerability allows a local authenticated user to execute arbitrary code.
net/socket.c in the Linux kernel 3.19 before 3.19.3 does not validate certain range data for (1) sendto and (2) recvfrom system calls, which allows local users to gain privileges by leveraging a subsystem that uses the copy_from_iter function in the iov_iter interface, as demonstrated by the Bluetooth subsystem.
Remediation
Install update from vendor's website.