CVE-2015-3290: Linux Kernel

High severity, CVSS 7.2. EPSS: 1.1% chance of exploitation in the next 30 days.

arch/x86/entry/entry_64.S in the Linux kernel before 4.1.6 on the x86_64 platform improperly relies on espfix64 during nested NMI processing, which allows local users to gain privileges by triggering an NMI within a certain instruction window.

Affected products

  • Linux Linux Kernel: before 3.12.47 (fixed in 3.12.47); from 3.13, before 3.14.54 (fixed in 3.14.54); from 3.15, before 3.16.35 (fixed in 3.16.35); from 3.17, before 3.18.22 (fixed in 3.18.22); from 3.19, before 4.1.6 (fixed in 4.1.6)

Published 2015-08-31. Last modified 2026-06-17.