Candidate: CVE-2015-3285 PublicDate: 2015-08-12 14:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3285 http://www.openafs.org/pages/security/OPENAFS-SA-2015-004.txt Description: The pioctl for the OSD FS command in OpenAFS before 1.6.13 uses the wrong pointer when writing the results of the RPC, which allows local users to cause a denial of service (memory corruption and kernel panic) via a crafted OSD FS command. Ubuntu-Description: Notes: Bugs: https://bugs.launchpad.net/ubuntu/+source/openafs/+bug/1481373 Priority: medium Discovered-by: Assigned-to: CVSS: Patches_openafs: upstream: http://www.openafs.org/pages/security/openafs-sa-2015-004.patch upstream_openafs: released (1.6.13) precise_openafs: released (1.6.1-1+ubuntu0.6) trusty_openafs: released (1.6.7-1ubuntu1.1) trusty/esm_openafs: DNE (trusty was released [1.6.7-1ubuntu1.1]) vivid_openafs: ignored (reached end-of-life) vivid/stable-phone-overlay_openafs: DNE vivid/ubuntu-core_openafs: DNE wily_openafs: not-affected (1.6.14-1) devel_openafs: not-affected (1.6.15-1)