CVE-2015-2041 describes a vulnerability in the Linux kernel, specifically in the net/llc/sysctl_net_llc.c component, affecting versions prior to 3.19. This flaw, caused by an incorrect data type in a sysctl table, allows local users to potentially extract sensitive information from kernel memory. With a CVSS score of 4.6, this vulnerability is considered medium severity, requiring local access with low attack complexity. Successful exploitation could lead to partial confidentiality, integrity, and availability impacts. There is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. Furthermore, the vulnerability has received minimal community discussion and media coverage, indicating low public awareness and interest.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10CPE matchmatch criteria | cpe:2.3:o:suse:suse_linux_enterprise_server:10:sp4:*:*:*:*:*:* | ||
<= 3.18.7CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.