CVE-2015-3290

Linux kernel <4.1.6 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2015-3290. PoCs published by Andrew Lutomirski.

AI-analyzed exploit summary This exploit targets CVE-2015-3290, a privilege escalation vulnerability in Linux x86_64 systems (3.13 and newer) due to a flaw in NMI handling and espfix64. It manipulates nested NMIs to corrupt return context and achieve kernel-level execution.

Description

arch/x86/entry/entry_64.S in the Linux kernel before 4.1.6 on the x86_64 platform improperly relies on espfix64 during nested NMI processing, which allows local users to gain privileges by triggering an NMI within a certain instruction window.

Exploits (1)

exploitdb WORKING POC
by Andrew Lutomirski · clocallinux_x86-64
https://www.exploit-db.com/exploits/37722

This exploit targets CVE-2015-3290, a privilege escalation vulnerability in Linux x86_64 systems (3.13 and newer) due to a flaw in NMI handling and espfix64. It manipulates nested NMIs to corrupt return context and achieve kernel-level execution.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Complex
Reliability
Reliable
Target: Linux kernel x86_64 (3.13 and newer)
No auth needed
Prerequisites: Untrusted code execution on the target system · Ability to trigger nested NMIs
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (15)

Core 15
Core References
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=1243465
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2015/08/04/8
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/76004
Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/37722/
Third Party Advisory, VDB Entry vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2689-1
Third Party Advisory, VDB Entry vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2690-1
Third Party Advisory, VDB Entry vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2691-1
Third Party Advisory, VDB Entry vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2688-1
Third Party Advisory, VDB Entry vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00011.html
Third Party Advisory, VDB Entry vendor-advisory x_refsource_debian
http://www.debian.org/security/2015/dsa-3313
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2015/07/22/7
Third Party Advisory, VDB Entry vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2687-1

Scores

EPSS 0.0029
EPSS Percentile 53.2%

Details

CWE
CWE-264
Status published
Products (1)
linux/linux_kernel < 3.12.47
Published Aug 31, 2015
Tracked Since Feb 18, 2026