CVE-2015-3288: Linux Kernel

High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.

mm/memory.c in the Linux kernel before 4.1.4 mishandles anonymous pages, which allows local users to gain privileges or cause a denial of service (page tainting) via a crafted application that triggers writing to page zero.

Affected products

  • Linux Linux Kernel: before 3.2.71 (fixed in 3.2.71); from 3.4, before 3.4.111 (fixed in 3.4.111); from 3.10, before 3.10.86 (fixed in 3.10.86); from 3.12, before 3.12.47 (fixed in 3.12.47); from 3.14, before 3.14.50 (fixed in 3.14.50); from 3.16, before 3.16.35 (fixed in 3.16.35); …

Published 2016-10-16. Last modified 2026-06-17.