CVE-2015-2672
MEDIUMLinux Kernel < 3.19.1 - Improper Input Validation
Title source: ruleDescription
The xsave/xrstor implementation in arch/x86/include/asm/xsave.h in the Linux kernel before 3.19.2 creates certain .altinstr_replacement pointers and consequently does not provide any protection against instruction faulting, which allows local users to cause a denial of service (panic) by triggering a fault, as demonstrated by an unaligned memory operand or a non-canonical address memory operand.
Scores
CVSS v3
5.5
EPSS
0.0004
EPSS Percentile
12.7%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Classification
CWE
CWE-20
Status
draft
Affected Products (1)
linux/linux_kernel
< 3.19.1
Timeline
Published
May 02, 2016
Tracked Since
Feb 18, 2026