Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2015-1805

25
FAUCET Score

CVE-2015-1805 is a critical vulnerability in the Linux kernel's pipe_read and pipe_write implementations (fs/pipe.c) affecting versions before 3.16, including Google Android and Linux distributions. This flaw, dubbed an "I/O vector array overrun," stems from improper handling of failed __copy_to_user_inatomic and __copy_from_user_inatomic calls. It carries a high CVSS score of 7.2, indicating a local attack vector with low complexity, allowing unauthenticated local users to cause a denial of service (system crash) or potentially gain privileges. While not listed in CISA's KEV catalog and lacking public Metasploit or ExploitDB modules, the vulnerability garnered significant community discussion and media attention, including reports of Google issuing an emergency patch, suggesting awareness and potential for exploitation.

Impacted Technologies

VendorProductVersion(s)CPE
4.4.3CPE matchmatch criteria
cpe:2.3:o:google:android:4.4.3:*:*:*:*:*:*:*
5.0.1CPE matchmatch criteria
cpe:2.3:o:google:android:5.0.1:*:*:*:*:*:*:*
5.1CPE matchmatch criteria
cpe:2.3:o:google:android:5.1:*:*:*:*:*:*:*
5.1.1CPE matchmatch criteria
cpe:2.3:o:google:android:5.1.1:*:*:*:*:*:*:*
6.0CPE matchmatch criteria
cpe:2.3:o:google:android:6.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

7.2HIGH

AV:L/AC:L/Au:N/C:C/I:C/A:C

Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
Access Vector
LOCAL
Access Complexity
LOW
Authentication
NONE
Exploitability Score
3.9
Impact Score
10.0
CvssVersion
2.0

Exploit Intelligence

EPSS Score
1.23%
Probability of exploitation in next 30 days
EPSS Percentile
65.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0123 is in the 83rd percentile among its peer group of 3,241 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (11)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: kernel-0:2.6.18-406.el5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5.6 Long LifeFixed in: kernel-0:2.6.18-238.56.1.el5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5.9 Long LifeFixed in: kernel-0:2.6.18-348.31.2.el5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: kernel-0:2.6.32-504.23.4.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6.2 Advanced Update SupportFixed in: kernel-0:2.6.32-220.63.2.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6.4 Advanced Update SupportFixed in: kernel-0:2.6.32-358.62.1.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6.5 Extended Update SupportFixed in: kernel-0:2.6.32-431.59.1.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-rt-0:3.10.0-229.7.2.rt56.141.6.el7_1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-0:3.10.0-229.7.2.ael7b
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise MRG 2Fixed in: kernel-rt-1:3.10.0-229.rt56.153.el6rt
View patch
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux Extended Update Support 5.6Fixed in: kernel

Vendor Advisories (1)

redhatCVE-2015-1805Important

kernel: pipe: iovec overrun leading to memory corruption

Jun 2, 2015

References

git.kernel.org / cgit/linux/kernel/git/torvalds/linux.git/commit
git.kernel.org / cgit/linux/kernel/git/torvalds/linux.git/commit
lists.opensuse.org / opensuse-security-announce/2015-07/msg00023.html
lists.opensuse.org / opensuse-security-announce/2015-07/msg00049.html
lists.opensuse.org / opensuse-security-announce/2015-09/msg00004.html
lists.opensuse.org / opensuse-security-announce/2015-09/msg00007.html
lists.opensuse.org / opensuse-security-announce/2015-09/msg00008.html
lists.opensuse.org / opensuse-security-announce/2015-09/msg00009.html
lists.opensuse.org / opensuse-security-announce/2015-09/msg00010.html
lists.opensuse.org / opensuse-security-announce/2015-09/msg00011.html
lists.opensuse.org / opensuse-security-announce/2015-09/msg00018.html
lists.opensuse.org / opensuse-security-announce/2015-09/msg00021.html
rhn.redhat.com / errata/RHSA-2015-1042.html
rhn.redhat.com / errata/RHSA-2015-1081.html
rhn.redhat.com / errata/RHSA-2015-1082.html
rhn.redhat.com / errata/RHSA-2015-1120.html
rhn.redhat.com / errata/RHSA-2015-1137.html
rhn.redhat.com / errata/RHSA-2015-1138.html
rhn.redhat.com / errata/RHSA-2015-1190.html
rhn.redhat.com / errata/RHSA-2015-1199.html
rhn.redhat.com / errata/RHSA-2015-1211.html
bugzilla.redhat.com / show_bug.cgi
github.com / torvalds/linux/commit/637b58c2887e5e57850865839cc75f59184b23d1
github.com / torvalds/linux/commit/f0d1bec9d58d4c038d0ac958c9af82be6eb18045
source.android.com / security/bulletin/2016-04-02.html
source.android.com / security/bulletin/2016-05-01.html
debian.org / security/2015/dsa-3290
openwall.com / lists/oss-security/2015/06/06/2
oracle.com / technetwork/topics/security/linuxbulletinoct2015-2719645.html
securityfocus.com / bid/74951
securitytracker.com / id/1032454
ubuntu.com / usn/USN-2679-1
ubuntu.com / usn/USN-2680-1
ubuntu.com / usn/USN-2681-1
ubuntu.com / usn/USN-2967-1
ubuntu.com / usn/USN-2967-2