CVE-2015-7312: Canonical Ubuntu Linux
Medium severity, CVSS 4.4. EPSS: 0.4% chance of exploitation in the next 30 days.
Multiple race conditions in the Advanced Union Filesystem (aufs) aufs3-mmap.patch and aufs4-mmap.patch patches for the Linux kernel 3.x and 4.x allow local users to cause a denial of service (use-after-free and BUG) or possibly gain privileges via a (1) madvise or (2) msync system call, related to mm/madvise.c and mm/msync.c.
Affected products
- Canonical Ubuntu Linux: version 14.04 only
- Debian Debian Linux: version 8.0 only
- Linux Linux Kernel: from 3.0.0, up to and including 3.19.8; from 4.0.0, up to and including 4.20.15
Published 2015-11-16. Last modified 2026-06-17.