CVE-2015-3636 – Linux Foundation / Linux Kernel – Use after free
CVE-2015-3636 is a use after free vulnerability impacting Linux kernel before versions 4.0.3. An exploit was observed in open source and a link to an exploit was shared in the underground. Security researchers claimed the vulnerability was used to support rooting malware deployment operations.
Summary:
CVE-2015-3636 is a use after free vulnerability impacting Linux kernel before versions 4.0.3. An exploit was observed in open source and a link to an exploit was shared in the underground. Security researchers claimed the vulnerability was used to support rooting malware deployment operations.
PoC Links(if available):
GitHub commit PoC –
https://github.com/fi01/CVE-2015-3636
Known Counter Measures:
Linux Foundation addressed the vulnerability in Linux Kernel version 4.0.3.
Links to patches(if available)
https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.0.3