Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2015-2041

14
FAUCET Score

CVE-2015-2041 describes a vulnerability in the Linux kernel, specifically in the net/llc/sysctl_net_llc.c component, affecting versions prior to 3.19. This flaw, caused by an incorrect data type in a sysctl table, allows local users to potentially extract sensitive information from kernel memory. With a CVSS score of 4.6, this vulnerability is considered medium severity, requiring local access with low attack complexity. Successful exploitation could lead to partial confidentiality, integrity, and availability impacts. There is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. Furthermore, the vulnerability has received minimal community discussion and media coverage, indicating low public awareness and interest.

Impacted Technologies

VendorProductVersion(s)CPE
10CPE matchmatch criteria
cpe:2.3:o:suse:suse_linux_enterprise_server:10:sp4:*:*:*:*:*:*
<= 3.18.7CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
All Versions ImpactedCPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

4.6MEDIUM

AV:L/AC:L/Au:N/C:P/I:P/A:P

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
Access Vector
LOCAL
Access Complexity
LOW
Authentication
NONE
Exploitability Score
3.9
Impact Score
6.4
CvssVersion
2.0

Exploit Intelligence

EPSS Score
0.47%
Probability of exploitation in next 30 days
EPSS Percentile
38.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0047 is in the 72nd percentile among its peer group of 3,050 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2015-2041Low

kernel: llc: information leak in llc2_timeout_table

Feb 20, 2015

References

git.kernel.org
lists.opensuse.org / opensuse-security-announce/2015-04/msg00020.html
Mailing List
lists.opensuse.org / opensuse-security-announce/2015-07/msg00023.html
Mailing List
lists.opensuse.org / opensuse-security-announce/2015-08/msg00011.html
Mailing List
lists.opensuse.org / opensuse-security-announce/2015-09/msg00004.html
Mailing List
bugzilla.redhat.com / show_bug.cgi
Issue Tracking
github.com / torvalds/linux/commit/6b8d9117ccb4f81b1244aafa7bc70ef8fa45fc49
Third Party Advisory
debian.org / security/2015/dsa-3237
Third Party Advisory
openwall.com / lists/oss-security/2015/02/20/19
Mailing List
securityfocus.com / bid/72729
Third Party AdvisoryVDB Entry
ubuntu.com / usn/USN-2560-1
Third Party Advisory
ubuntu.com / usn/USN-2561-1
Third Party Advisory
ubuntu.com / usn/USN-2562-1
Third Party Advisory
ubuntu.com / usn/USN-2563-1
Third Party Advisory
ubuntu.com / usn/USN-2564-1
Third Party Advisory
ubuntu.com / usn/USN-2565-1
Third Party Advisory