CVE-2015-5364

high
Published 2015-08-31 · Modified 2026-05-06
CVSS v3
CVSS v2
7.8
VIR risk
7.8

Description

The (1) udp_recvmsg and (2) udpv6_recvmsg functions in the Linux kernel before 4.0.6 do not properly consider yielding a processor, which allows remote attackers to cause a denial of service (system hang) via incorrect checksums within a UDP packet flood.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2015-5364

vendor Authored 2026-05-27

Vendor advisory: security@debian.org — http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.0.6

vendor Authored 2026-05-27

Vendor advisory: security@debian.org — http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=beb39db59d14990e401e235faf66a6b9b31240b0

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2015-5364.html

OS impact

OSVersionStatusFixed in
suse slesaffected
debian debianbookwormfixed4.0.7-1
debian debianbullseyefixed4.0.7-1
debian debianforkyfixed4.0.7-1
debian debiansidfixed4.0.7-1
debian debiantrixiefixed4.0.7-1
ubuntu ubuntu12.04affected
ubuntu ubuntu14.04affected
ubuntu ubuntu15.04affected
debian debian7.0affected
debian debian8.0affected
linux linux-kernelaffected3.2.70

References

CWEs

CWE-399

Verify integrity in audit chain (admin only). AS-IS.