Vulnerability Name:

CVE-2015-8970 (CCN-120131)

Assigned:2015-12-17
Published:2015-12-17
Updated:2023-02-13
Summary:crypto/algif_skcipher.c in the Linux kernel before 4.4.2 does not verify that a setkey operation has been performed on an AF_ALG socket before an accept system call is processed, which allows local users to cause a denial of service (NULL pointer dereference and system crash) via a crafted application that does not supply a key, related to the lrw_crypt function in crypto/lrw.c.
CVSS v3 Severity:5.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
4.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
6.2 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
5.4 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
5.5 Medium (REDHAT CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
4.8 Medium (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
CVSS v2 Severity:4.9 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
4.9 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
4.9 Medium (REDHAT CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
Vulnerability Type:CWE-476
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2015-8970

Source: CCN
Type: Linux Kernel GIT Repository
crypto: algif_skcipher - Require setkey before accept(2)

Source: secalert@redhat.com
Type: Issue Tracking, Patch, Vendor Advisory
secalert@redhat.com

Source: CCN
Type: IBM Security Bulletin T1026731 (PowerKVM)
Vulnerabilities in the Linux kernel affect PowerKVM

Source: CCN
Type: IBM Security Bulletin 2011746 (QRadar Network Security)
IBM QRadar Network Security is affected by vulnerabilities in Linux kernel

Source: secalert@redhat.com
Type: Release Notes
secalert@redhat.com

Source: secalert@redhat.com
Type: Mailing List, Third Party Advisory
secalert@redhat.com

Source: CCN
Type: BID-94217
Linux Kernel 'crypto/lrw.c' Local Denial of Service Vulnerability

Source: secalert@redhat.com
Type: Third Party Advisory, VDB Entry
secalert@redhat.com

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: secalert@redhat.com
Type: Issue Tracking
secalert@redhat.com

Source: XF
Type: UNKNOWN
linux-kernel-cve20158970-dos(120131)

Source: secalert@redhat.com
Type: Issue Tracking, Patch, Third Party Advisory
secalert@redhat.com

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2015-8970

Vulnerable Configuration:Configuration RedHat 1:
  • cpe:/o:redhat:enterprise_linux:7:*:*:*:*:*:*:*
  • Configuration RedHat 2:
  • cpe:/o:redhat:enterprise_linux:7::client:*:*:*:*:*
  • Configuration RedHat 3:
  • cpe:/o:redhat:enterprise_linux:7::computenode:*:*:*:*:*
  • Configuration RedHat 4:
  • cpe:/o:redhat:enterprise_linux:7::server:*:*:*:*:*
  • Configuration RedHat 5:
  • cpe:/o:redhat:enterprise_linux:7::workstation:*:*:*:*:*
  • Configuration RedHat 6:
  • cpe:/a:redhat:rhel_extras_rt:7:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/o:linux:linux_kernel:4.4.1:*:*:*:*:*:*:*
  • AND
  • cpe:/a:ibm:powerkvm:3.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:qradar_network_security:5.4:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20158970
    V
    CVE-2015-8970
    2022-09-02
    oval:org.opensuse.security:def:33794
    P
    Security update for libvirt (Important)
    2022-01-10
    oval:org.opensuse.security:def:30290
    P
    Security update for net-snmp (Important)
    2022-01-05
    oval:org.opensuse.security:def:34013
    P
    Security update for glib-networking (Important)
    2021-12-13
    oval:org.opensuse.security:def:31305
    P
    Security update for the Linux Kernel (Live Patch 39 for SLE 12 SP3) (Important)
    2021-11-19
    oval:org.opensuse.security:def:34583
    P
    Security update for binutils (Moderate)
    2021-11-02
    oval:org.opensuse.security:def:34558
    P
    Security update for libqt5-qtsvg (Moderate)
    2021-10-11
    oval:org.opensuse.security:def:30133
    P
    Security update for glibc (Moderate)
    2021-10-06
    oval:org.opensuse.security:def:33980
    P
    Security update for sqlite3 (Important)
    2021-09-23
    oval:org.opensuse.security:def:30241
    P
    Security update for openexr (Important)
    2021-09-02
    oval:org.opensuse.security:def:34519
    P
    Security update for aspell (Important)
    2021-08-25
    oval:org.opensuse.security:def:31253
    P
    Security update for the Linux Kernel (Live Patch 34 for SLE 12 SP3) (Important)
    2021-08-25
    oval:org.opensuse.security:def:31249
    P
    Security update for python-PyYAML (Important)
    2021-08-24
    oval:org.opensuse.security:def:33691
    P
    Security update for qemu (Important)
    2021-07-28
    oval:org.opensuse.security:def:32134
    P
    Security update for openexr (Important)
    2021-06-24
    oval:org.opensuse.security:def:30219
    P
    Security update for libgcrypt (Important)
    2021-06-24
    oval:org.opensuse.security:def:34470
    P
    Security update for xterm (Important)
    2021-06-18
    oval:org.opensuse.security:def:36145
    P
    guestfs-data-1.20.12-0.18.70 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:36186
    P
    libfreebl3-3.17.3-0.8.11 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:34441
    P
    Security update for libX11 (Moderate)
    2021-05-26
    oval:org.opensuse.security:def:30076
    P
    Security update for djvulibre (Important)
    2021-05-19
    oval:org.opensuse.security:def:30186
    P
    Security update for libnettle (Important)
    2021-04-28
    oval:org.opensuse.security:def:34412
    P
    Security update for ImageMagick (Moderate)
    2021-04-20
    oval:org.opensuse.security:def:34397
    P
    Security update for xen (Important)
    2021-04-06
    oval:org.opensuse.security:def:33783
    P
    Security update for python (Moderate)
    2021-03-16
    oval:org.opensuse.security:def:35289
    P
    Security update for python (Moderate)
    2021-03-16
    oval:org.opensuse.security:def:34653
    P
    Security update for s390-tools (Important)
    2021-03-12
    oval:org.opensuse.security:def:34652
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:31354
    P
    Security update for wpa_supplicant (Important)
    2021-03-09
    oval:org.opensuse.security:def:33782
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:30033
    P
    Security update for python-cryptography (Important)
    2021-03-02
    oval:org.opensuse.security:def:34627
    P
    Security update for jasper (Important)
    2021-02-16
    oval:org.opensuse.security:def:35265
    P
    Security update for python-urllib3 (Moderate)
    2021-02-03
    oval:org.opensuse.security:def:31216
    P
    Security update for postgresql, postgresql12, postgresql13 (Important)
    2021-01-26
    oval:org.opensuse.security:def:32096
    P
    Security update for dnsmasq (Important)
    2021-01-19
    oval:org.opensuse.security:def:34664
    P
    Security update for the Linux Kernel (Moderate)
    2021-01-12
    oval:org.opensuse.security:def:33923
    P
    Security update for java-1_7_1-ibm (Moderate)
    2021-01-04
    oval:org.opensuse.security:def:34333
    P
    Security update for openssl-1_1 (Important)
    2020-12-10
    oval:org.opensuse.security:def:33877
    P
    Security update for mutt (Important)
    2020-12-07
    oval:org.opensuse.security:def:29300
    P
    Security update for python-cryptography (Moderate)
    2020-12-04
    oval:org.opensuse.security:def:29947
    P
    Security update for gdm (Important)
    2020-12-03
    oval:org.opensuse.security:def:29989
    P
    Security update for libssh2_org (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27385
    P
    cvs-doc on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31393
    P
    Security update for pam_pkcs11 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29163
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:27712
    P
    Security update for bind (Important)
    2020-12-01
    oval:org.opensuse.security:def:28273
    P
    Security update for mozilla-nspr (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31030
    P
    Security update for java-1_7_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:27487
    P
    libssh2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31458
    P
    Security update for postgresql91 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27724
    P
    Security update for elfutils
    2020-12-01
    oval:org.opensuse.security:def:28478
    P
    Security update for zlib (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29587
    P
    Security update for apache2-mod_perl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34884
    P
    Security update for curl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30372
    P
    Security update for wireshark (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27540
    P
    ppp-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30642
    P
    Security update for xorg-x11-libXfixes
    2020-12-01
    oval:org.opensuse.security:def:27916
    P
    Security update for xorg-x11-libX11
    2020-12-01
    oval:org.opensuse.security:def:34069
    P
    Security update for libxml2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28566
    P
    Security update for Linux kernel
    2020-12-01
    oval:org.opensuse.security:def:29671
    P
    Security update for dhcpcd
    2020-12-01
    oval:org.opensuse.security:def:35040
    P
    Security update for ipsec-tools (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30476
    P
    Security update for bind (Important)
    2020-12-01
    oval:org.opensuse.security:def:28222
    P
    Security update for libsndfile (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30654
    P
    Security update for ImageMagick (Important)
    2020-12-01
    oval:org.opensuse.security:def:28055
    P
    Security update for dhcp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34284
    P
    Security update for Python
    2020-12-01
    oval:org.opensuse.security:def:28626
    P
    Security update for Mozilla Firefox
    2020-12-01
    oval:org.opensuse.security:def:29890
    P
    Security update for kernel-source (Important)
    2020-12-01
    oval:org.opensuse.security:def:30534
    P
    Security update for java-1_6_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:26809
    P
    puppet on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30860
    P
    Security update for e2fsprogs (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28290
    P
    Security update for mysql (Important)
    2020-12-01
    oval:org.opensuse.security:def:34372
    P
    Security update for tiff (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27844
    P
    Security update for mozilla-nspr, mozilla-nss
    2020-12-01
    oval:org.opensuse.security:def:35397
    P
    Security update for openssh (Important)
    2020-12-01
    oval:org.opensuse.security:def:26884
    P
    dhcpcd on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31007
    P
    Security update for java-1_6_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:28392
    P
    Security update for samba (Important)
    2020-12-01
    oval:org.opensuse.security:def:27856
    P
    Security update for postgresql94 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34109
    P
    Security update for mutt
    2020-12-01
    oval:org.opensuse.security:def:35463
    P
    Security update for php53 (Important)
    2020-12-01
    oval:org.opensuse.security:def:29773
    P
    Security update for glibc (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27093
    P
    boost-license on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28446
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:35119
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:33596
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:28048
    P
    Security update for curl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34255
    P
    Security update for postgresql91 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30329
    P
    Security update for tomcat6 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29857
    P
    Security update for the Linux Kernel
    2020-12-01
    oval:org.opensuse.security:def:27234
    P
    logwatch on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29128
    P
    Security update for the Linux Kernel (Critical)
    2020-12-01
    oval:org.opensuse.security:def:33608
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:28189
    P
    Security update for krb5 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30392
    P
    Security update for Xen
    2020-12-01
    oval:org.opensuse.security:def:27438
    P
    libcgroup-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31414
    P
    Security update for php53 (Important)
    2020-12-01
    oval:org.opensuse.security:def:27713
    P
    Security update for bind (Important)
    2020-12-01
    oval:org.opensuse.security:def:33827
    P
    Security update for gnome-session (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28425
    P
    Security update for wireshark (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31067
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:29586
    P
    Security update for apache2-mod_nss (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34748
    P
    Security update for MozillaFirefox, MozillaFirefox-branding-SLE and mozilla-nss (Important)
    2020-12-01
    oval:org.opensuse.security:def:27526
    P
    opensc-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27788
    P
    Security update for PostgreSQL 9.1
    2020-12-01
    oval:org.opensuse.security:def:28527
    P
    Security update for wget (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29598
    P
    Security update for audiofile (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34983
    P
    Security update for ghostscript-library (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30427
    P
    Security update for xorg-x11-libs (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27584
    P
    xorg-x11-libXfixes-devel-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30643
    P
    Security update for xorg-x11-libXp
    2020-12-01
    oval:org.opensuse.security:def:27998
    P
    Security update for MozillaFirefox, mozilla-nspr, mozilla-nss (Important)
    2020-12-01
    oval:org.opensuse.security:def:34226
    P
    Security update for php5 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28582
    P
    Security update for libssh2
    2020-12-01
    oval:org.opensuse.security:def:35305
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:29803
    P
    Security update for inn (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35130
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:30515
    P
    Security update for ghostscript
    2020-12-01
    oval:org.opensuse.security:def:28257
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:26808
    P
    postgresql on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30728
    P
    Security update for Mozilla Firefox
    2020-12-01
    oval:org.opensuse.security:def:28139
    P
    Security update for java-1_7_1-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:29264
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:35348
    P
    Security update for mysql (Important)
    2020-12-01
    oval:org.opensuse.security:def:30578
    P
    Security update for nagios-nrpe, nagios-plugins-nrpe
    2020-12-01
    oval:org.opensuse.security:def:26820
    P
    squid on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30950
    P
    Security update for glibc (Important)
    2020-12-01
    oval:org.opensuse.security:def:28343
    P
    Security update for php53 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27845
    P
    Recommended update for openldap2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35436
    P
    Security update for openvpn (Important)
    2020-12-01
    oval:org.opensuse.security:def:29772
    P
    Security update for glibc (Important)
    2020-12-01
    oval:org.opensuse.security:def:27012
    P
    perl-HTML-Parser on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31094
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:28431
    P
    Security update for wireshark (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35079
    P
    Security update for java-1_7_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:27920
    P
    Security update for xorg-x11-libXp
    2020-12-01
    oval:org.opensuse.security:def:34166
    P
    Security update for openssl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35507
    P
    Security update for postgresql10 (Important)
    2020-12-01
    oval:org.opensuse.security:def:29784
    P
    Security update for gpg2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:27150
    P
    jakarta-commons-fileupload on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28490
    P
    Security update for curl (Important)
    2020-12-01
    oval:org.opensuse.security:def:33597
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:28132
    P
    Security update for jasper (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30348
    P
    Security update for vim (Important)
    2020-12-01
    oval:com.redhat.rhsa:def:20171842
    P
    RHSA-2017:1842: kernel security, bug fix, and enhancement update (Important)
    2017-08-01
    oval:com.redhat.rhsa:def:20172077
    P
    RHSA-2017:2077: kernel-rt security, bug fix, and enhancement update (Important)
    2017-08-01
    oval:com.ubuntu.xenial:def:201589700000000
    V
    CVE-2015-8970 on Ubuntu 16.04 LTS (xenial) - medium.
    2016-11-28
    oval:com.ubuntu.disco:def:201589700000000
    V
    CVE-2015-8970 on Ubuntu 19.04 (disco) - medium.
    2016-11-28
    oval:com.ubuntu.bionic:def:201589700000000
    V
    CVE-2015-8970 on Ubuntu 18.04 LTS (bionic) - medium.
    2016-11-28
    oval:com.ubuntu.xenial:def:20158970000
    V
    CVE-2015-8970 on Ubuntu 16.04 LTS (xenial) - medium.
    2016-11-27
    oval:com.ubuntu.cosmic:def:20158970000
    V
    CVE-2015-8970 on Ubuntu 18.10 (cosmic) - medium.
    2016-11-27
    oval:com.ubuntu.precise:def:20158970000
    V
    CVE-2015-8970 on Ubuntu 12.04 LTS (precise) - medium.
    2016-11-27
    oval:com.ubuntu.cosmic:def:201589700000000
    V
    CVE-2015-8970 on Ubuntu 18.10 (cosmic) - medium.
    2016-11-27
    oval:com.ubuntu.artful:def:20158970000
    V
    CVE-2015-8970 on Ubuntu 17.10 (artful) - medium.
    2016-11-27
    oval:com.ubuntu.trusty:def:20158970000
    V
    CVE-2015-8970 on Ubuntu 14.04 LTS (trusty) - medium.
    2016-11-27
    oval:com.ubuntu.bionic:def:20158970000
    V
    CVE-2015-8970 on Ubuntu 18.04 LTS (bionic) - medium.
    2016-11-27
    BACK
    linux linux kernel 4.4.1
    ibm powerkvm 3.1
    ibm qradar network security 5.4