Security Advisory

CVE-2015-8962

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2016-11-16 04:49:00
Last updated 2024-08-06 08:36:30
Assigner google_android
State PUBLISHED

Description

Double free vulnerability in the sg_common_write function in drivers/scsi/sg.c in the Linux kernel before 4.4 allows local users to gain privileges or cause a denial of service (memory corruption and system crash) by detaching a device during an SG_IO ioctl call.