CVE-2015-5707

Integer overflow in the sg_start_req function in drivers/scsi/sg.c in the Linux kernel 2.6.x through 4.x before 4.1 allows local users to cause a denial of service or possibly have unspecified other impact via a large iov_count value in a write request.

Published: 2015-10-19 Last update: 2026-06-16 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2015-5707 is rated Low Risk (32.2/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.49%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2015-5707

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 0.09% 0.49% +0.41%
2 2025-03-30 0.40% 0.09% -0.31%
3 2025-03-29 0.40%

Full EPSS history (6 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2015-5707

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
4.6 2.0 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P Click to expand
Access vector (AV:L)
Requires local access to the target system.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:P)
Partial confidentiality impact.
Integrity impact (I:P)
Partial integrity impact.
Availability impact (A:P)
Partial availability impact.
3.9 6.4 [email protected]

Weakness enumeration for CVE-2015-5707

OS Trackers for CVE-2015-5707

vendor priority summary link
debian not yet assigned CVE-2015-5707 not yet assigned priority: Debian including 1 source packages (linux), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. https://security-tracker.debian.org/tracker/CVE-2015-5707
redhat medium https://access.redhat.com/security/cve/CVE-2015-5707
ubuntu medium CVE-2015-5707 medium priority: Ubuntu including 31 source packages (linux, linux-2.6, …), 261 status rows across 9 suites (precise, trusty, upstream, utopic, vivid, wily, xenial, yakkety, zesty): DNE 180, released 39, ignored 25, not-affected 17. https://ubuntu.com/security/CVE-2015-5707

Affected software / configurations for CVE-2015-5707

Vendor Product Version Raw CPE
linux linux_kernel >= 2.6.0, < 4.1.0 cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
canonical ubuntu_linux 12.04 cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*
canonical ubuntu_linux 14.04 cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
canonical ubuntu_linux 15.04 cpe:2.3:o:canonical:ubuntu_linux:15.04:*:*:*:*:*:*:*
debian debian_linux 7.0 cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
debian debian_linux 8.0 cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
suse suse_linux_enterprise_desktop 11 cpe:2.3:o:suse:suse_linux_enterprise_desktop:11:sp3:*:*:*:*:*:*
suse suse_linux_enterprise_server 11 cpe:2.3:o:suse:suse_linux_enterprise_server:11:sp2:*:*:ltss:*:*:*
suse suse_linux_enterprise_server 11 cpe:2.3:o:suse:suse_linux_enterprise_server:11:sp3:*:*:*:*:*:*
suse suse_linux_enterprise_server 11 cpe:2.3:o:suse:suse_linux_enterprise_server:11:sp3:*:*:*:vmware:*:*

References for CVE-2015-5707

URL Tags
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=451a2886b6bf90e2fb378f7c46c655450fb96e81 Patch Vendor Advisory
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=fdc81f45e9f57858da6351836507fbcf1b7583ee Patch Vendor Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00004.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00018.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00021.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00026.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00027.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00028.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00029.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00030.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00031.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00032.html Mailing List Third Party Advisory
http://www.debian.org/security/2015/dsa-3329 Third Party Advisory
http://www.openwall.com/lists/oss-security/2015/08/01/6 Mailing List Third Party Advisory
http://www.securityfocus.com/bid/76145 Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1033521 Third Party Advisory VDB Entry
http://www.ubuntu.com/usn/USN-2733-1 Third Party Advisory
http://www.ubuntu.com/usn/USN-2734-1 Third Party Advisory
http://www.ubuntu.com/usn/USN-2737-1 Third Party Advisory
http://www.ubuntu.com/usn/USN-2738-1 Third Party Advisory
http://www.ubuntu.com/usn/USN-2750-1 Third Party Advisory
http://www.ubuntu.com/usn/USN-2759-1 Third Party Advisory
http://www.ubuntu.com/usn/USN-2760-1 Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1250030 Issue Tracking Third Party Advisory
https://github.com/torvalds/linux/commit/451a2886b6bf90e2fb378f7c46c655450fb96e81 Patch Third Party Advisory
https://github.com/torvalds/linux/commit/fdc81f45e9f57858da6351836507fbcf1b7583ee Patch Third Party Advisory
https://source.android.com/security/bulletin/2017-07-01 Third Party Advisory
cvelogic Threat Intelligence