CVE-2015-8812: Canonical Ubuntu Linux
Critical severity, CVSS 9.8. EPSS: 14.5% chance of exploitation in the next 30 days.
drivers/infiniband/hw/cxgb3/iwch_cm.c in the Linux kernel before 4.5 does not properly identify error conditions, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via crafted packets.
Affected products
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 15.10 only
- Linux Linux Kernel: before 3.2.78 (fixed in 3.2.78); from 3.3, before 3.10.99 (fixed in 3.10.99); from 3.11, before 3.12.56 (fixed in 3.12.56); from 3.13, before 3.14.63 (fixed in 3.14.63); from 3.15, before 3.16.35 (fixed in 3.16.35); from 3.17, before 3.18.31 (fixed in 3.18.31); …
- Novell Suse Linux Enterprise Real Time Extension: version 12 only
Published 2016-04-27. Last modified 2026-06-17.