CVE-2015-4001: kernel: ozwpan: integer signedness error leading to heap buffer overflow

Severity: Critical

CVSS Score: 7.5

Integer signedness error in the oz_hcd_get_desc_cnf function in drivers/staging/ozwpan/ozhcd.c in the OZWPAN driver in the Linux kernel through 4.0.5 allows remote attackers to cause a denial of service (system crash) or possibly execute arbitrary code via a crafted packet.