Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2015-5157

19
FAUCET Score

CVE-2015-5157 describes a privilege escalation vulnerability in the Linux kernel (before 4.1.6) on x86_64 systems, specifically affecting the arch/x86/entry/entry_64.S component. This flaw allows a local user to gain elevated privileges by triggering a Non-Maskable Interrupt (NMI) during userspace execution, leading to mishandled IRET faults. With a CVSS score of 7.2 (High), this vulnerability has a low attack complexity and requires local access, but could result in complete compromise of confidentiality, integrity, and availability. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
6.0CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
6.0CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux_hpc_node:6.0:*:*:*:*:*:*:*
6.0CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
6.7.zCPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux_server_eus:6.7.z:*:*:*:*:*:*:*
6.0CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

7.2HIGH

AV:L/AC:L/Au:N/C:C/I:C/A:C

Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
Access Vector
LOCAL
Access Complexity
LOW
Authentication
NONE
Exploitability Score
3.9
Impact Score
10.0
CvssVersion
2.0

Exploit Intelligence

EPSS Score
0.62%
Probability of exploitation in next 30 days
EPSS Percentile
46.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0062 is in the 68th percentile among its peer group of 3,241 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (18)

microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 ARMFixed in: 5.15.153.1-1
microsoftpatch availablevia msrc
Product: azl3 kernel 6.6.14.1-4 on Azure Linux 3.0Fixed in: 6.6.22.1-2
microsoftpatch availablevia msrc
Product: cbl2 kernel 5.15.153.1-1 on CBL Mariner 2.0Fixed in: 5.15.153.1-1
microsoftpatch availablevia msrc
Product: cbl2 kernel 5.15.148.2-2 on CBL Mariner 2.0Fixed in: 5.15.153.1-1
microsoftpatch availablevia msrc
Product: 16839-17084Fixed in: 6.6.22.1-2
microsoftpatch availablevia msrc
Product: 16839-16817Fixed in: 6.6.22.1-2
microsoftpatch availablevia msrc
Product: 19779-17084Fixed in: 6.6.22.1-2
microsoftpatch availablevia msrc
Product: 16838-16823Fixed in: 5.15.153.1-1
microsoftpatch availablevia msrc
Product: 19793-17086Fixed in: 5.15.153.1-1
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 x64Fixed in: 6.6.22.1-2
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 ARMFixed in: 6.6.22.1-2
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 x64Fixed in: 5.15.153.1-1
microsoftpatch availablevia msrc
Product: azl3 kernel 6.6.22.1-2 on Azure Linux 3.0Fixed in: 6.6.22.1-2
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-0:3.10.0-327.10.1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise MRG 2Fixed in: kernel-rt-1:3.10.0-327.rt56.171.el6rt
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: kernel-0:2.6.32-573.26.1.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-rt-0:3.10.0-327.10.1.rt56.211.el7_2
View patch
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: kernel

Vendor Advisories (3)

microsoft2024-Jun/CVE-2015-5157

CVE-2015-5157

Jun 11, 2024
microsoft2015-Aug/CVE-2015-5157Important

arch/x86/entry/entry_64.S in the Linux kernel before 4.1.6 on the x86_64 platform mishandles IRET faults in processing NMIs that occurred during userspace execution which might allow local users to gain privileges by triggering an NMI.

Aug 2, 2015
redhatCVE-2015-5157Moderate

kernel: x86-64: IRET faults during NMIs processing

Jul 22, 2015

References

git.kernel.org / cgit/linux/kernel/git/torvalds/linux.git/commit
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2015-10/msg00009.html
Third Party AdvisoryVDB Entry
lists.opensuse.org / opensuse-security-announce/2015-11/msg00035.html
Third Party AdvisoryVDB Entry
lists.opensuse.org / opensuse-security-announce/2015-12/msg00026.html
Third Party AdvisoryVDB Entry
lists.opensuse.org / opensuse-security-announce/2015-12/msg00031.html
Third Party AdvisoryVDB Entry
lists.opensuse.org / opensuse-security-announce/2016-02/msg00013.html
Third Party AdvisoryVDB Entry
rhn.redhat.com / errata/RHSA-2016-0185.html
Third Party AdvisoryVDB Entry
rhn.redhat.com / errata/RHSA-2016-0212.html
Third Party AdvisoryVDB Entry
rhn.redhat.com / errata/RHSA-2016-0224.html
Third Party AdvisoryVDB Entry
rhn.redhat.com / errata/RHSA-2016-0715.html
Third Party AdvisoryVDB Entry
github.com / torvalds/linux/commit/9b6e6a8334d56354853f9c255d1395c2ba570e0a
Third Party Advisory
debian.org / security/2015/dsa-3313
Third Party AdvisoryVDB Entry
kernel.org / pub/linux/kernel/v4.x/ChangeLog-4.1.6
Vendor Advisory
openwall.com / lists/oss-security/2015/07/22/7
Mailing List
oracle.com / technetwork/topics/security/linuxbulletinapr2016-2952096.html
Third Party Advisory
oracle.com / technetwork/topics/security/linuxbulletinjan2016-2867209.html
Third Party Advisory
securityfocus.com / bid/76005
Third Party AdvisoryVDB Entry
ubuntu.com / usn/USN-2687-1
Third Party AdvisoryVDB Entry
ubuntu.com / usn/USN-2688-1
Third Party AdvisoryVDB Entry
ubuntu.com / usn/USN-2689-1
Third Party AdvisoryVDB Entry
ubuntu.com / usn/USN-2690-1
Third Party AdvisoryVDB Entry
ubuntu.com / usn/USN-2691-1
Third Party AdvisoryVDB Entry