CVE-2015-5364: Canonical Ubuntu Linux

High severity, CVSS 7.8. EPSS: 6.1% chance of exploitation in the next 30 days.

The (1) udp_recvmsg and (2) udpv6_recvmsg functions in the Linux kernel before 4.0.6 do not properly consider yielding a processor, which allows remote attackers to cause a denial of service (system hang) via incorrect checksums within a UDP packet flood.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 15.04 only
  • Debian Debian Linux: version 7.0 only; version 8.0 only
  • Linux Linux Kernel: before 3.2.70 (fixed in 3.2.70); from 3.3, before 3.4.109 (fixed in 3.4.109); from 3.5, before 3.10.81 (fixed in 3.10.81); from 3.11, before 3.12.44 (fixed in 3.12.44); from 3.13, before 3.14.45 (fixed in 3.14.45); from 3.15, before 3.16.35 (fixed in 3.16.35); …
  • Red Hat Enterprise Linux Server Aus: version 6.5 only

Published 2015-08-31. Last modified 2026-06-17.