Double Free Vulnerability in Linux Kernel's sg_common_write Function

Double Free Vulnerability in Linux Kernel's sg_common_write Function

CVE-2015-8962 · HIGH Severity

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Double free vulnerability in the sg_common_write function in drivers/scsi/sg.c in the Linux kernel before 4.4 allows local users to gain privileges or cause a denial of service (memory corruption and system crash) by detaching a device during an SG_IO ioctl call.

Learn more about our Cis Benchmark Audit For Distribution Independent Linux.