CVE-2015-8830 affects older 64-bit Linux kernels where asynchronous I/O (io_submit) can submit an oversized IOCB_CMD_PWRITE request to network-protocol sendmsg handlers. In the L2TP PPP path, the length can integer-overflow during socket-buffer allocation, corrupting kernel heap memory and potentially allowing an unprivileged local user to escalate privileges. Google Project Zero validated a proof of concept on a fully patched Ubuntu 14.04 LTS server; 3.10- and 3.18-based kernels were affected, and 64-bit Android devices using Linux 3.10 were considered likely vulnerable.
Linux kernel changes to AIO request setup added initialization handling and capped single-vector request lengths at MAX_RW_COUNT, preventing oversized requests from reaching vulnerable protocol handlers. The flaw was fixed upstream after disclosure and is distinct from CVE-2012-6701, an earlier AIO validation issue addressed in Linux v3.5-rc1. Organizations operating legacy Linux or Android kernels should ensure vendor security updates incorporating the AIO length-validation fix are deployed.

Get the actors, campaigns, and ATT&CK mapping behind it.
5 events from the most recent confirmed update back to the earliest known activity.
Google Project Zero marked the Linux L2TP PPP socket sendmsg vulnerability fixed. The issue affected older 64-bit branches including 3.10 and 3.18; the proof of concept had been tested on Ubuntu 14.04 LTS.
A patch addressing the Linux io_submit L2TP sendmsg integer-overflow vulnerability was released on the Linux Kernel Mailing List.
Google Project Zero reported that an unprivileged local user could use io_submit with an oversized IOCB_CMD_PWRITE request to trigger an integer overflow in the L2TP PPP sendmsg path, causing kernel heap corruption and potentially local privilege escalation.
Red Hat stated that RHEL 5 was not affected by CVE-2015-8830, while RHEL 6 and RHEL 7 were affected or had been affected.
A Linux kernel patch changed fs/aio.c to clamp oversized single-vector AIO request lengths to MAX_RW_COUNT and initialize iov_iter during AIO request setup. The patch does not identify a CVE or explicitly state a security impact.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
4 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open sourcebugs.chromium.org
Open sourcegit.kernel.org
Open sourcegit.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.