Your submission was sent successfully! Close

You have successfully unsubscribed! Close

CVE-2015-1573

Published: 2 May 2016

The nft_flush_table function in net/netfilter/nf_tables_api.c in the Linux kernel before 3.18.5 mishandles the interaction between cross-chain jumps and ruleset flushes, which allows local users to cause a denial of service (panic) by leveraging the CAP_NET_ADMIN capability.

Notes

AuthorNote
jdstrand
android kernels (flo, goldfish, grouper, maguro, mako and manta) are
not supported on the Ubuntu Touch 14.10 and earlier preview kernels
linux-lts-saucy no longer receives official support
linux-lts-quantal no longer receives official support

Priority

Medium

CVSS 3 base score: 5.5

Status

Package Release Status
linux
Launchpad, Ubuntu, Debian
lucid Not vulnerable

precise Not vulnerable

trusty Not vulnerable

upstream
Released (3.19~rc5)
utopic Not vulnerable

vivid Not vulnerable
(3.18.0-13.14)
wily Not vulnerable
(3.19.0-15.15)
Patches:
Introduced by

b9ac12ef099707f405d7478009564302d7ed8393

Fixed by a2f18db0c68fec96631c10cad9384c196e9008ac
linux-2.6
Launchpad, Ubuntu, Debian
lucid Does not exist

precise Does not exist

trusty Does not exist

upstream
Released (3.19~rc5)
utopic Does not exist

vivid Does not exist

wily Does not exist

linux-armadaxp
Launchpad, Ubuntu, Debian
lucid Does not exist

precise Not vulnerable

trusty Does not exist

upstream
Released (3.19~rc5)
utopic Does not exist

vivid Does not exist

wily Does not exist

This package is not directly supported by the Ubuntu Security Team
linux-ec2
Launchpad, Ubuntu, Debian
lucid Not vulnerable

precise Does not exist

trusty Does not exist

upstream
Released (3.19~rc5)
utopic Does not exist

vivid Does not exist

wily Does not exist

linux-flo
Launchpad, Ubuntu, Debian
lucid Does not exist

precise Does not exist

trusty Does not exist
(trusty was ignored)
upstream
Released (3.19~rc5)
utopic Not vulnerable

vivid Not vulnerable

wily Not vulnerable

linux-fsl-imx51
Launchpad, Ubuntu, Debian
lucid Ignored
(reached end-of-life, does not affect buildd)
precise Does not exist

trusty Does not exist

upstream
Released (3.19~rc5)
utopic Does not exist

vivid Does not exist

wily Does not exist

linux-goldfish
Launchpad, Ubuntu, Debian
lucid Does not exist

precise Does not exist

trusty Does not exist
(trusty was ignored)
upstream
Released (3.19~rc5)
utopic Not vulnerable

vivid Not vulnerable

wily Not vulnerable

linux-grouper
Launchpad, Ubuntu, Debian
lucid Does not exist

precise Does not exist

trusty Does not exist
(trusty was ignored)
upstream
Released (3.19~rc5)
utopic Ignored
(reached end-of-life)
vivid Does not exist

wily Does not exist

linux-linaro-omap
Launchpad, Ubuntu, Debian
lucid Does not exist

precise Ignored
(abandoned)
trusty Does not exist

upstream
Released (3.19~rc5)
utopic Does not exist

vivid Does not exist

wily Does not exist

linux-linaro-shared
Launchpad, Ubuntu, Debian
lucid Does not exist

precise Ignored
(abandoned)
trusty Does not exist

upstream
Released (3.19~rc5)
utopic Does not exist

vivid Does not exist

wily Does not exist

linux-linaro-vexpress
Launchpad, Ubuntu, Debian
lucid Does not exist

precise Ignored
(abandoned)
trusty Does not exist

upstream
Released (3.19~rc5)
utopic Does not exist

vivid Does not exist

wily Does not exist

linux-lts-quantal
Launchpad, Ubuntu, Debian
lucid Does not exist

precise Not vulnerable

trusty Does not exist

upstream
Released (3.19~rc5)
utopic Does not exist

vivid Does not exist

wily Does not exist

This package is not directly supported by the Ubuntu Security Team
linux-lts-raring
Launchpad, Ubuntu, Debian
lucid Does not exist

precise Ignored
(was needs-triage now end-of-life)
trusty Does not exist

upstream
Released (3.19~rc5)
utopic Does not exist

vivid Does not exist

wily Does not exist

linux-lts-saucy
Launchpad, Ubuntu, Debian
lucid Does not exist

precise Not vulnerable

trusty Does not exist

upstream
Released (3.19~rc5)
utopic Does not exist

vivid Does not exist

wily Does not exist

This package is not directly supported by the Ubuntu Security Team
linux-lts-trusty
Launchpad, Ubuntu, Debian
lucid Does not exist

precise Not vulnerable

trusty Does not exist

upstream
Released (3.19~rc5)
utopic Does not exist

vivid Does not exist

wily Does not exist

linux-lts-utopic
Launchpad, Ubuntu, Debian
lucid Does not exist

precise Does not exist

trusty Does not exist
(trusty was not-affected)
upstream
Released (3.19~rc5)
utopic Does not exist

vivid Does not exist

wily Does not exist

linux-lts-vivid
Launchpad, Ubuntu, Debian
lucid Does not exist

precise Does not exist

trusty Does not exist
(trusty was not-affected [3.19.0-18.18~14.04.1])
upstream
Released (3.19~rc5)
utopic Does not exist

vivid Does not exist

wily Does not exist

linux-maguro
Launchpad, Ubuntu, Debian
lucid Does not exist

precise Does not exist

trusty Does not exist
(trusty was ignored)
upstream
Released (3.19~rc5)
utopic Does not exist

vivid Does not exist

wily Does not exist

linux-mako
Launchpad, Ubuntu, Debian
lucid Does not exist

precise Does not exist

trusty Does not exist
(trusty was ignored)
upstream
Released (3.19~rc5)
utopic Not vulnerable

vivid Not vulnerable

wily Not vulnerable

linux-manta
Launchpad, Ubuntu, Debian
lucid Does not exist

precise Does not exist

trusty Does not exist
(trusty was ignored)
upstream
Released (3.19~rc5)
utopic Not vulnerable

vivid Not vulnerable

wily Not vulnerable

linux-mvl-dove
Launchpad, Ubuntu, Debian
lucid Ignored
(reached end-of-life)
precise Does not exist

trusty Does not exist

upstream
Released (3.19~rc5)
utopic Does not exist

vivid Does not exist

wily Does not exist

linux-qcm-msm
Launchpad, Ubuntu, Debian
lucid Ignored
(abandoned)
precise Ignored
(abandoned)
trusty Does not exist

upstream
Released (3.19~rc5)
utopic Does not exist

vivid Does not exist

wily Does not exist

linux-raspi2
Launchpad, Ubuntu, Debian
precise Does not exist

trusty Does not exist

upstream
Released (3.19~rc5)
vivid Does not exist

wily Not vulnerable
(4.2.0-1008.12)
linux-ti-omap4
Launchpad, Ubuntu, Debian
lucid Does not exist

precise Not vulnerable

trusty Does not exist

upstream
Released (3.19~rc5)
utopic Does not exist

vivid Does not exist

wily Does not exist