---
title: "CVE-2015-8787\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2015-8787?format=md
keywords: index, follow
---

# CVE-2015-8787

Publication date 31 December 2015

Last updated 4 July 2026

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**9.8 · Critical**

[Score breakdown](https://ubuntu.com/security/CVE-2015-8787?format=md#impact-score)

Toggle side navigation

## Description

The nf\_nat\_redirect\_ipv4 function in net/netfilter/nf\_nat\_redirect.c in the
Linux kernel before 4.4 allows remote attackers to cause a denial of
service (NULL pointer dereference and system crash) or possibly have
unspecified other impact by sending certain IPv4 packets to an incompletely
configured interface, a related issue to CVE-2003-1604.

### From the Ubuntu Security Team

It was discovered that the netfilter Network Address Translation (NAT)
implementation did not ensure that data structures were initialized when
handling IPv4 addresses. An attacker could use this to cause a denial of
service (system crash).

[Read the notes from the security team](https://ubuntu.com/security/CVE-2015-8787?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| linux | 16.10 yakkety | Not affected |
| 16.04 LTS xenial | Not affected |
| 15.10 wily | Fixed 4.2.0-27.32 |
| 15.04 vivid | Fixed 3.19.0-49.55 |
| 14.04 LTS trusty | Not affected |
| 12.04 LTS precise | Not affected |
| linux-2.6 | 16.10 yakkety | Not in release |
| 16.04 LTS xenial | Not in release |
| 15.10 wily | Not in release |
| 15.04 vivid | Not in release |
| 14.04 LTS trusty | Not in release |
| 12.04 LTS precise | Not in release |
| linux-armadaxp | 16.10 yakkety | Not in release |
| 16.04 LTS xenial | Not in release |
| 15.10 wily | Not in release |
| 15.04 vivid | Not in release |
| 14.04 LTS trusty | Not in release |
| 12.04 LTS precise | Not affected |
| linux-aws | 16.10 yakkety | Not in release |
| 16.04 LTS xenial | Not affected |
| 14.04 LTS trusty | Not affected |
| 12.04 LTS precise | Not in release |
| linux-flo | 16.10 yakkety | Not affected |
| 16.04 LTS xenial | Not in release |
| 15.10 wily | Not affected |
| 15.04 vivid | Not affected |
| 14.04 LTS trusty | Not in release |
| 12.04 LTS precise | Not in release |
| linux-fsl-imx51 | 16.10 yakkety | Not in release |
| 16.04 LTS xenial | Not in release |
| 15.10 wily | Not in release |
| 15.04 vivid | Not in release |
| 14.04 LTS trusty | Not in release |
| 12.04 LTS precise | Not in release |
| linux-gke | 16.10 yakkety | Not in release |
| 16.04 LTS xenial | Not affected |
| 14.04 LTS trusty | Not in release |
| 12.04 LTS precise | Not in release |
| linux-goldfish | 16.10 yakkety | Not affected |
| 16.04 LTS xenial | Not in release |
| 15.10 wily | Not affected |
| 15.04 vivid | Not affected |
| 14.04 LTS trusty | Not in release |
| 12.04 LTS precise | Not in release |
| linux-grouper | 16.10 yakkety | Not in release |
| 16.04 LTS xenial | Not in release |
| 15.10 wily | Not in release |
| 15.04 vivid | Not in release |
| 14.04 LTS trusty | Not in release |
| 12.04 LTS precise | Not in release |
| linux-hwe | 16.10 yakkety | Not in release |
| 16.04 LTS xenial | Not affected |
| 14.04 LTS trusty | Not in release |
| 12.04 LTS precise | Not in release |
| linux-hwe-edge | 16.10 yakkety | Not in release |
| 16.04 LTS xenial | Not affected |
| 14.04 LTS trusty | Not in release |
| 12.04 LTS precise | Not in release |
| linux-linaro-omap | 16.10 yakkety | Not in release |
| 16.04 LTS xenial | Not in release |
| 15.10 wily | Not in release |
| 15.04 vivid | Not in release |
| 14.04 LTS trusty | Not in release |
| 12.04 LTS precise | Ignored end of life |
| linux-linaro-shared | 16.10 yakkety | Not in release |
| 16.04 LTS xenial | Not in release |
| 15.10 wily | Not in release |
| 15.04 vivid | Not in release |
| 14.04 LTS trusty | Not in release |
| 12.04 LTS precise | Ignored end of life |
| linux-linaro-vexpress | 16.10 yakkety | Not in release |
| 16.04 LTS xenial | Not in release |
| 15.10 wily | Not in release |
| 15.04 vivid | Not in release |
| 14.04 LTS trusty | Not in release |
| 12.04 LTS precise | Ignored end of life |
| linux-lts-quantal | 16.10 yakkety | Not in release |
| 16.04 LTS xenial | Not in release |
| 15.10 wily | Not in release |
| 15.04 vivid | Not in release |
| 14.04 LTS trusty | Not in release |
| 12.04 LTS precise | Ignored end of life |
| linux-lts-raring | 16.10 yakkety | Not in release |
| 16.04 LTS xenial | Not in release |
| 15.10 wily | Not in release |
| 15.04 vivid | Not in release |
| 14.04 LTS trusty | Not in release |
| 12.04 LTS precise | Ignored end of life |
| linux-lts-saucy | 16.10 yakkety | Not in release |
| 16.04 LTS xenial | Not in release |
| 15.10 wily | Not in release |
| 15.04 vivid | Not in release |
| 14.04 LTS trusty | Not in release |
| 12.04 LTS precise | Ignored end of life |
| linux-lts-trusty | 16.10 yakkety | Not in release |
| 16.04 LTS xenial | Not in release |
| 15.10 wily | Not in release |
| 15.04 vivid | Not in release |
| 14.04 LTS trusty | Not in release |
| 12.04 LTS precise | Not affected |
| linux-lts-utopic | 16.10 yakkety | Not in release |
| 16.04 LTS xenial | Not in release |
| 15.10 wily | Not in release |
| 15.04 vivid | Not in release |
| 14.04 LTS trusty | Not in release |
| 12.04 LTS precise | Not in release |
| linux-lts-vivid | 16.10 yakkety | Not in release |
| 16.04 LTS xenial | Not in release |
| 15.10 wily | Not in release |
| 15.04 vivid | Not in release |
| 14.04 LTS trusty | Fixed 3.19.0-49.55~14.04.1 |
| 12.04 LTS precise | Not in release |
| linux-lts-wily | 16.10 yakkety | Not in release |
| 16.04 LTS xenial | Not in release |
| 15.10 wily | Not in release |
| 15.04 vivid | Not in release |
| 14.04 LTS trusty | Fixed 4.2.0-27.32~14.04.1 |
| 12.04 LTS precise | Not in release |
| linux-lts-xenial | 16.10 yakkety | Not in release |
| 16.04 LTS xenial | Not in release |
| 15.10 wily | Not in release |
| 15.04 vivid | Not in release |
| 14.04 LTS trusty | Not affected |
| 12.04 LTS precise | Not in release |
| linux-maguro | 16.10 yakkety | Not in release |
| 16.04 LTS xenial | Not in release |
| 15.10 wily | Not in release |
| 15.04 vivid | Not in release |
| 14.04 LTS trusty | Not in release |
| 12.04 LTS precise | Not in release |
| linux-mako | 16.10 yakkety | Not affected |
| 16.04 LTS xenial | Not in release |
| 15.10 wily | Not affected |
| 15.04 vivid | Not affected |
| 14.04 LTS trusty | Not in release |
| 12.04 LTS precise | Not in release |
| linux-manta | 16.10 yakkety | Not in release |
| 16.04 LTS xenial | Not in release |
| 15.10 wily | Not affected |
| 15.04 vivid | Not affected |
| 14.04 LTS trusty | Not in release |
| 12.04 LTS precise | Not in release |
| linux-qcm-msm | 16.10 yakkety | Not in release |
| 16.04 LTS xenial | Not in release |
| 15.10 wily | Not in release |
| 15.04 vivid | Not in release |
| 14.04 LTS trusty | Not in release |
| 12.04 LTS precise | Ignored end of life |
| linux-raspi2 | 16.10 yakkety | Not affected |
| 16.04 LTS xenial | Not affected |
| 15.10 wily | Fixed 4.2.0-1022.29 |
| 15.04 vivid | Not in release |
| 14.04 LTS trusty | Not in release |
| 12.04 LTS precise | Not in release |
| linux-snapdragon | 16.10 yakkety | Not affected |
| 16.04 LTS xenial | Not affected |
| 15.10 wily | Not in release |
| 14.04 LTS trusty | Not in release |
| 12.04 LTS precise | Not in release |
| linux-ti-omap4 | 16.10 yakkety | Not in release |
| 16.04 LTS xenial | Not in release |
| 15.10 wily | Not in release |
| 15.04 vivid | Not in release |
| 14.04 LTS trusty | Not in release |
| 12.04 LTS precise | Not affected |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2015-8787?format=md#patch-details)

## Notes

---

### [jdstrand](https://launchpad.net/~jdstrand)

android kernels (flo, goldfish, grouper, maguro, mako and manta) are
not supported on the Ubuntu Touch 14.10 and earlier preview kernels
linux-lts-saucy no longer receives official support
linux-lts-quantal no longer receives official support

---

### [seth-arnold](https://launchpad.net/~seth-arnold)

The "Introducing" commit message says IPv6 patch would follow --
we should investigate if it has the same flaw, if it ever followed.

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| linux | * Introduced by   [8b13edd](https://git.kernel.org/linus/8b13eddfdf04cbfa561725cfc42d6868fe896f56),   fixed by   [94f9cd8](https://git.kernel.org/linus/94f9cd81436c85d8c3a318ba92e236ede73752fc) |

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

9.8 · Critical

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | Low |
  | Privileges required | None |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | High |
  | Integrity impact | High |
  | Availability impact | High |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 9.8 · Critical |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8787)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2015-8787)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2015-8787)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2015-8787)

### Related Ubuntu Security Notices (USN)

+ [USN-2889-2](https://usn.ubuntu.com/USN-2889-2)
+ Linux kernel (Vivid HWE) vulnerabilities
+ 2 February 2016

+ [USN-2890-2](https://usn.ubuntu.com/USN-2890-2)
+ Linux kernel (Wily HWE) vulnerabilities
+ 2 February 2016

+ [USN-2889-1](https://usn.ubuntu.com/USN-2889-1)
+ Linux kernel vulnerabilities
+ 2 February 2016

+ [USN-2890-3](https://usn.ubuntu.com/USN-2890-3)
+ Linux kernel (Raspberry Pi 2) vulnerabilities
+ 2 February 2016

+ [USN-2890-1](https://usn.ubuntu.com/USN-2890-1)
+ Linux kernel vulnerabilities
+ 2 February 2016

### Other references

* <https://bugzilla.redhat.com/show_bug.cgi?id=1300731>
* <https://lkml.org/lkml/2015/12/2/618>
* <http://www.openwall.com/lists/oss-security/2016/01/27/6>
* <https://www.cve.org/CVERecord?id=CVE-2015-8787>
