CVE-2015-1338: Apport Project Apport

High severity, CVSS 7.2. EPSS: 0.9% chance of exploitation in the next 30 days.

kernel_crashdump in Apport before 2.19 allows local users to cause a denial of service (disk consumption) or possibly gain privileges via a (1) symlink or (2) hard link attack on /var/crash/vmcore.log.

Affected products

  • Apport Project Apport: up to and including 2.18.1
  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 15.04 only

Published 2015-10-01. Last modified 2026-06-17.