CVE-2015-4004: Canonical Ubuntu Linux

High severity, CVSS 8.5. EPSS: 8.1% chance of exploitation in the next 30 days.

The OZWPAN driver in the Linux kernel through 4.0.5 relies on an untrusted length field during packet parsing, which allows remote attackers to obtain sensitive information from kernel memory or cause a denial of service (out-of-bounds read and system crash) via a crafted packet.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 15.10 only
  • Linux Linux Kernel: from 3.4, before 4.3 (fixed in 4.3)

Published 2015-06-07. Last modified 2026-06-17.