CVE-2015-2666: Fedoraproject Fedora
Medium severity, CVSS 6.9. EPSS: 0.4% chance of exploitation in the next 30 days.
Stack-based buffer overflow in the get_matching_model_microcode function in arch/x86/kernel/cpu/microcode/intel_early.c in the Linux kernel before 4.0 allows context-dependent attackers to gain privileges by constructing a crafted microcode header and leveraging root privileges for write access to the initrd.
Affected products
- Fedoraproject Fedora: version 21 only
- Linux Linux Kernel: from 3.9, before 3.10.83 (fixed in 3.10.83); from 3.11, before 3.12.40 (fixed in 3.12.40); from 3.13, before 3.14.47 (fixed in 3.14.47); from 3.15, before 3.16.35 (fixed in 3.16.35); from 3.17, before 3.18.19 (fixed in 3.18.19)
Published 2015-05-27. Last modified 2026-06-17.