CVE-2015-8787

critical
Published 2016-02-08 · Modified 2026-05-06
CVSS v3
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2
10.0
VIR risk
9.8

Description

The nf_nat_redirect_ipv4 function in net/netfilter/nf_nat_redirect.c in the Linux kernel before 4.4 allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by sending certain IPv4 packets to an incompletely configured interface, a related issue to CVE-2003-1604.

Predictions

Exploit likelihood
97%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2015-8787

vendor Authored 2026-05-27

Vendor advisory: security@debian.org — https://github.com/torvalds/linux/commit/94f9cd81436c85d8c3a318ba92e236ede73752fc

vendor Authored 2026-05-27

Vendor advisory: security@debian.org — http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=94f9cd81436c85d8c3a318ba92e236ede73752fc

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2015-8787.html

OS impact

OSVersionStatusFixed in
suse slesaffected
debian debianbookwormfixed4.3.5-1
debian debianbullseyefixed4.3.5-1
debian debianforkyfixed4.3.5-1
debian debiansidfixed4.3.5-1
debian debiantrixiefixed4.3.5-1
linux linux-kernelaffected4.1.31

References

CWEs

CWE-476

Verify integrity in audit chain (admin only). AS-IS.