CVE-2015-1465: Canonical Ubuntu Linux

High severity, CVSS 7.8. EPSS: 6.5% chance of exploitation in the next 30 days.

The IPv4 implementation in the Linux kernel before 3.18.8 does not properly consider the length of the Read-Copy Update (RCU) grace period for redirecting lookups in the absence of caching, which allows remote attackers to cause a denial of service (memory consumption or system crash) via a flood of packets.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 14.10 only
  • Linux Linux Kernel: from 3.10.50, before 3.10.70 (fixed in 3.10.70); from 3.12.26, before 3.12.38 (fixed in 3.12.38); from 3.14.14, before 3.14.34 (fixed in 3.14.34); from 3.15.7, before 3.16.35 (fixed in 3.16.35); from 3.17, before 3.18.8 (fixed in 3.18.8)

Published 2015-04-05. Last modified 2026-06-17.