7.2
CVSSv2

CVE-2015-5157

Published: 31/08/2015 Updated: 14/03/2024
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 642
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

arch/x86/entry/entry_64.S in the Linux kernel prior to 4.1.6 on the x86_64 platform mishandles IRET faults in processing NMIs that occurred during userspace execution, which might allow local users to gain privileges by triggering an NMI.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat enterprise linux server eus 6.7.z

redhat enterprise linux hpc node 6.0

redhat enterprise linux desktop 6.0

redhat enterprise linux server 6.0

redhat enterprise linux workstation 6.0

linux linux kernel

Vendor Advisories

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation or denial of service CVE-2015-3290 Andy Lutomirski discovered that the Linux kernel does not properly handle nested NMIs A local, unprivileged user could use this flaw for privilege escalation CVE-2015-3291 Andy Lutomirski di ...
Several security issues were fixed in the kernel ...
Several security issues were fixed in the kernel ...
Several security issues were fixed in the kernel ...
Several security issues were fixed in the kernel ...
Several security issues were fixed in the kernel ...
A flaw was found in the way the Linux kernel handled IRET faults during the processing of NMIs An unprivileged, local user could use this flaw to crash the system or, potentially (although highly unlikely), escalate their privileges on the system ...