CVE-2015-4004
EPSS 8.1%
Description
The OZWPAN driver in the Linux kernel through 4.0.5 relies on an untrusted length field during packet parsing, which allows remote attackers to obtain sensitive information from kernel memory or cause a denial of service (out-of-bounds read and system crash) via a crafted packet.
How to fix CVE-2015-4004
To remediate CVE-2015-4004, upgrade the affected package to a fixed version below.
- Debian/linux—upgrade to 4.3-1 or later
Is CVE-2015-4004 being exploited?
Moderate — EPSS is 8.1%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 4.3-1