CVE-2015-4036: Linux Kernel
High severity, CVSS 7.2. EPSS: 0.6% chance of exploitation in the next 30 days.
Array index error in the tcm_vhost_make_tpg function in drivers/vhost/scsi.c in the Linux kernel before 4.0 might allow guest OS users to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted VHOST_SCSI_SET_ENDPOINT ioctl call. NOTE: the affected function was renamed to vhost_scsi_make_tpg before the vulnerability was announced.
Affected products
- Linux Linux Kernel: after 3.6, before 3.10.90 (fixed in 3.10.90); from 3.11, before 3.12.44 (fixed in 3.12.44); from 3.13, before 3.14.57 (fixed in 3.14.57); from 3.15, before 3.16.35 (fixed in 3.16.35); from 3.17, before 3.18.25 (fixed in 3.18.25); from 3.19, before 4.0 (fixed in 4.0); …
Published 2015-08-31. Last modified 2026-06-17.