VendorsLinuxlinux_kernel3.15
Vulnerabilities

Linux Kernel 3.15

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

11CVEs
CVE-2026-43283
net: ethernet: ec_bhf: Fix dma_free_coherent() dma handle
Published 2026-05-06 · Analyzed
8.8EPSS 0.002
CVE-2025-21664
dm thin: make get_first_thin use rcu-safe list first function
Published 2025-01-21 · Modified
7.8EPSS 0.002
CVE-2014-8884
Stack-based buffer overflow in the ttusbdecfe_dvbs_diseqc_send_master_cmd function in drivers/media/usb/ttusb-dec/ttusbdecfe.c in the Linux kernel before 3.17.4 allows local users to cause a denial of service (system crash) or possibly gain privileges via a large message length in an ioctl call.
Published 2014-11-30 · Modified
6.1EPSS 0.006
CVE-2017-8106
The handle_invept function in arch/x86/kvm/vmx.c in the Linux kernel 3.12 through 3.15 allows privileged KVM guest OS users to cause a denial of service (NULL pointer dereference and host OS crash) via a single-context INVEPT instruction with a NULL EPT pointer.
Published 2017-04-24 · Modified
5.5EPSS 0.003
CVE-2026-31658
net: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit()
Published 2026-04-24 · Modified
5.5EPSS 0.002
CVE-2026-45948
ext4: fix memory leak in ext4_ext_shift_extents()
Published 2026-05-27 · Analyzed
5.5EPSS 0.002
CVE-2014-3688
The SCTP implementation in the Linux kernel before 3.17.4 allows remote attackers to cause a denial of service (memory consumption) by triggering a large number of chunks in an association's output queue, as demonstrated by ASCONF probes, related to net/sctp/inqueue.c and net/sctp/sm_statefuns.c.
Published 2014-11-30 · Modified
5.0EPSS 0.059
CVE-2014-7841
The sctp_process_param function in net/sctp/sm_make_chunk.c in the SCTP implementation in the Linux kernel before 3.17.4, when ASCONF is used, allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) via a malformed INIT chunk.
Published 2014-11-30 · Modified
5.0EPSS 0.052
CVE-2014-9090
The do_double_fault function in arch/x86/kernel/traps.c in the Linux kernel through 3.17.4 does not properly handle faults associated with the Stack Segment (SS) segment register, which allows local users to cause a denial of service (panic) via a modify_ldt system call, as demonstrated by sigreturn_32 in the linux-clock-tests test suite.
Published 2014-11-30 · Modified
4.9EPSS 0.004
CVE-2014-7842
Race condition in arch/x86/kvm/x86.c in the Linux kernel before 3.17.4 allows guest OS users to cause a denial of service (guest OS crash) via a crafted application that performs an MMIO transaction or a PIO transaction to trigger a guest userspace emulation error report, a similar issue to CVE-2010-5313.
Published 2014-11-30 · Modified
4.9EPSS 0.004
CVE-2014-8989
The Linux kernel through 3.17.4 does not properly restrict dropping of supplemental group memberships in certain namespace scenarios, which allows local users to bypass intended file permissions by leveraging a POSIX ACL containing an entry for the group category that is more restrictive than the entry for the other category, aka a "negative groups" issue, related to kernel/groups.c, kernel/uid16.c, and kernel/user_namespace.c.
Published 2014-11-30 · Modified
4.6EPSS 0.005