CVE-2015-4001: Linux Kernel

High severity, CVSS 9.0. EPSS: 7.1% chance of exploitation in the next 30 days.

Integer signedness error in the oz_hcd_get_desc_cnf function in drivers/staging/ozwpan/ozhcd.c in the OZWPAN driver in the Linux kernel through 4.0.5 allows remote attackers to cause a denial of service (system crash) or possibly execute arbitrary code via a crafted packet.

Affected products

  • Linux Linux Kernel: up to and including 4.0.5

Published 2015-06-07. Last modified 2026-06-17.