CVE-2015-4004

high
Published 2015-06-07 · Modified 2026-05-06
CVSS v3
CVSS v2
8.5
VIR risk
8.5

Description

The OZWPAN driver in the Linux kernel through 4.0.5 relies on an untrusted length field during packet parsing, which allows remote attackers to obtain sensitive information from kernel memory or cause a denial of service (out-of-bounds read and system crash) via a crafted packet.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2015-4004

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://lkml.org/lkml/2015/5/13/739

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed4.3-1
debian debianbullseyefixed4.3-1
debian debianforkyfixed4.3-1
debian debiansidfixed4.3-1
debian debiantrixiefixed4.3-1
linux linux-kernelaffected4.3
ubuntu ubuntu12.04affected
ubuntu ubuntu14.04affected
ubuntu ubuntu15.10affected

References

CWEs

CWE-119

Verify integrity in audit chain (admin only). AS-IS.