CVE-2015-4001
EPSS 7.1%
Description
Integer signedness error in the oz_hcd_get_desc_cnf function in drivers/staging/ozwpan/ozhcd.c in the OZWPAN driver in the Linux kernel through 4.0.5 allows remote attackers to cause a denial of service (system crash) or possibly execute arbitrary code via a crafted packet.
How to fix CVE-2015-4001
To remediate CVE-2015-4001, upgrade the affected package to a fixed version below.
- Debian/linux—upgrade to 4.1.3-1 or later
Is CVE-2015-4001 being exploited?
Moderate — EPSS is 7.1%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 4.1.3-1