CVE-2015-7613: Linux Kernel

Medium severity, CVSS 6.9. EPSS: 0.4% chance of exploitation in the next 30 days.

Race condition in the IPC object implementation in the Linux kernel through 4.2.3 allows local users to gain privileges by triggering an ipc_addid call that leads to uid and gid comparisons against uninitialized data, related to msg.c, shm.c, and util.c.

Affected products

  • Linux Linux Kernel: before 3.2.72 (fixed in 3.2.72); from 3.3, before 3.4.111 (fixed in 3.4.111); from 3.5, before 3.10.91 (fixed in 3.10.91); from 3.11, before 3.12.50 (fixed in 3.12.50); from 3.13, before 3.14.55 (fixed in 3.14.55); from 3.15, before 3.16.35 (fixed in 3.16.35); …

Published 2015-10-19. Last modified 2026-06-17.