CVE-2015-5157: Linux Kernel
High severity, CVSS 7.2. EPSS: 0.6% chance of exploitation in the next 30 days.
arch/x86/entry/entry_64.S in the Linux kernel before 4.1.6 on the x86_64 platform mishandles IRET faults in processing NMIs that occurred during userspace execution, which might allow local users to gain privileges by triggering an NMI.
Affected products
- Linux Linux Kernel: before 3.12.47 (fixed in 3.12.47); from 3.13, before 3.14.54 (fixed in 3.14.54); from 3.15, before 3.16.35 (fixed in 3.16.35); from 3.17, before 3.18.22 (fixed in 3.18.22); from 3.19, before 4.1.6 (fixed in 4.1.6)
- Red Hat Enterprise Linux Desktop: version 6.0 only
- Red Hat Enterprise Linux Hpc Node: version 6.0 only
- Red Hat Enterprise Linux Server: version 6.0 only
- Red Hat Enterprise Linux Server Eus: version 6.7.z only
- Red Hat Enterprise Linux Workstation: version 6.0 only
Published 2015-08-31. Last modified 2026-06-17.