CVE-2005-3055
published 2005-09-26CVE-2005-3055: Linux kernel 2.6.8 to 2.6.14-rc2 allows local users to cause a denial of service (kernel OOPS) via a userspace process that issues a USB Request Block (URB) to…
PriorityP410low2.1CVSS 2.0
AVLACLAuNCNINAP
EPSS
0.45%
37.2th percentile
Linux kernel 2.6.8 to 2.6.14-rc2 allows local users to cause a denial of service (kernel OOPS) via a userspace process that issues a USB Request Block (URB) to a USB device and terminates before the URB is finished, which leads to a stale pointer reference.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jp2p-2cxv-rx5x: Linux kernel 2
ghsa_unreviewed·2022-05-01
CVE-2005-3055 [LOW] CWE-20 GHSA-jp2p-2cxv-rx5x: Linux kernel 2
Linux kernel 2.6.8 to 2.6.14-rc2 allows local users to cause a denial of service (kernel OOPS) via a userspace process that issues a USB Request Block (URB) to a USB device and terminates before the URB is finished, which leads to a stale pointer reference.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2005-11-22
CVE-2005-3180 Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Linux kernel vulnerabilities
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
security flaw
vendor_redhat·2005-09-25·CVSS 2.1
CVE-2005-3055 [LOW] security flaw
security flaw
Linux kernel 2.6.8 to 2.6.14-rc2 allows local users to cause a denial of service (kernel OOPS) via a userspace process that issues a USB Request Block (URB) to a USB device and terminates before the URB is finished, which leads to a stale pointer reference.
Citrix
Citrix Security Bulletin CTX107705
vendor_citrix·CVSS 7.5
CVE-2005-3134 [HIGH] Citrix Security Bulletin CTX107705
Citrix Security Bulletin CTX107705
CVE References: CVE-2005-3134, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX105574
vendor_citrix·CVSS 7.5
CVE-2005-0821 [HIGH] Citrix Security Bulletin CTX105574
Citrix Security Bulletin CTX105574
CVE References: CVE-2005-0821, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX105762
vendor_citrix·CVSS 2.1
CVE-2005-0822 [LOW] Citrix Security Bulletin CTX105762
Citrix Security Bulletin CTX105762
CVE References: CVE-2005-0822, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX108208
vendor_citrix·CVSS 4.3
CVE-2005-3971 [MEDIUM] Citrix Security Bulletin CTX108208
Citrix Security Bulletin CTX108208
CVE References: CVE-2005-3971, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX108108
vendor_citrix·CVSS 2.1
CVE-2005-4412 [LOW] Citrix Security Bulletin CTX108108
Citrix Security Bulletin CTX108108
CVE References: CVE-2005-4412, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX108354
vendor_citrix·CVSS 7.5
CVE-2005-3652 [HIGH] Citrix Security Bulletin CTX108354
Citrix Security Bulletin CTX108354
CVE References: CVE-2005-3652, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2005-3055 security flaw
bugzilla·2018-08-16·CVSS 2.1
CVE-2005-3055 [LOW] CVE-2005-3055 security flaw
CVE-2005-3055 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Linux kernel 2.6.8 to 2.6.14-rc2 allows local users to cause a denial of service (kernel OOPS) via a userspace process that issues a USB Request Block (URB) to a USB device and terminates before the URB is finished, which leads to a stale pointer reference.
Bugzilla
Various kernel security issues - July thru October 2006
bugzilla·2006-07-24·CVSS 4.9
[MEDIUM] Various kernel security issues - July thru October 2006
Various kernel security issues - July thru October 2006
This bug will track the various kernel issues up to July 2006.
Discussion:
*** Bug 188935 has been marked as a duplicate of this bug. ***
---
*** Bug 190082 has been marked as a duplicate of this bug. ***
---
*** Bug 190083 has been marked as a duplicate of this bug. ***
---
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Here are updated kernel packages to QA for FC3:
* Sun Jul 16 2006 Marc Deslauriers
2.6.12-2.4.legacy_FC3
- - Added patches for:
CVE-2005-3359 (incorrect inrement/decrement in atm module)
CVE-2006-0555 (nfs: fix client panic using O_DIRECT)
CVE-2006-0741 (fix for ELF exec vulnerability on EM64T)
CVE-2006-0744 (fix for ELF exec vulnerability on EM64T)
CVE-2006-1525 (panic in ip_route_input() via inet_rtm_getro
Bugzilla
CVE-2005-3055 async usb devio oops (ipf)
bugzilla·2005-09-26·CVSS 2.1
CVE-2005-3055 [LOW] CVE-2005-3055 async usb devio oops (ipf)
CVE-2005-3055 async usb devio oops (ipf)
Although the issue below is for linux-2.6 the code in linux-2.4 looks pretty
much identical so this issue may affect RHEL2.1
+++ This bug was initially created as a clone of Bug #169260 +++
Harald Welte mailed the lkml on 20050925 with a report of how to cause a local
oops if a user has permissions to access an arbitrary usb device. I've rated
this as 'moderate' instead of 'important' due to that requirement. Although usb
permissions will be given automatically to console users, a DOS from a user who
has physical access to a machine is little extra risk and we ignore that from
the severity calculation.
See the following URL for the description and patch
http://marc.theaimsgroup.com/?l=linux-kernel&m=112766129313883
Discussion:
doesn't look lik
Bugzilla
CVE-2005-3055 async usb devio oops
bugzilla·2005-09-26·CVSS 2.1
CVE-2005-3055 [LOW] CVE-2005-3055 async usb devio oops
CVE-2005-3055 async usb devio oops
Although the issue below is for linux-2.6 the code in linux-2.4 looks pretty
much identical so this issue may affect RHEL2.1
+++ This bug was initially created as a clone of Bug #169260 +++
Harald Welte mailed the lkml on 20050925 with a report of how to cause a local
oops if a user has permissions to access an arbitrary usb device. I've rated
this as 'moderate' instead of 'important' due to that requirement. Although usb
permissions will be given automatically to console users, a DOS from a user who
has physical access to a machine is little extra risk and we ignore that from
the severity calculation.
See the following URL for the description and patch
http://marc.theaimsgroup.com/?l=linux-kernel&m=112766129313883
Discussion:
Created attachment 125
Bugzilla
CVE-2005-3055 async usb devio oops
bugzilla·2005-09-26·CVSS 2.1
CVE-2005-3055 [LOW] CVE-2005-3055 async usb devio oops
CVE-2005-3055 async usb devio oops
Harald Welte mailed the lkml on 20050925 with a report of how to cause a local
oops if a user has permissions to access an arbitrary usb device. I've rated
this as 'moderate' instead of 'important' due to that requirement. Although usb
permissions will be given automatically to console users, a DOS from a user who
has physical access to a machine is little extra risk and we ignore that from
the severity calculation.
See the following URL for the description and patch
http://marc.theaimsgroup.com/?l=linux-kernel&m=112766129313883
Discussion:
Created attachment 120010
Candidate #1 - Linus' patch adapted to RHEL 4
---
Regarding my proposal of checking if we still belong to the same process group
(or equivalent), it probably is not worth pursuing. Even
Bugzilla
CVE-2005-3055 async usb devio oops
bugzilla·2005-09-26·CVSS 2.1
CVE-2005-3055 [LOW] CVE-2005-3055 async usb devio oops
CVE-2005-3055 async usb devio oops
+++ This bug was initially created as a clone of Bug #169260 +++
Harald Welte mailed the lkml on 20050925 with a report of how to cause a local
oops if a user has permissions to access an arbitrary usb device. I've rated
this as 'moderate' instead of 'important' due to that requirement. Although usb
permissions will be given automatically to console users, a DOS from a user who
has physical access to a machine is little extra risk and we ignore that from
the severity calculation.
See the following URL for the description and patch
http://marc.theaimsgroup.com/?l=linux-kernel&m=112766129313883
Discussion:
(See followup from Linus; proposed patch won't be applied)
---
I have verified that RHEL 3 does not give access by default, both before
and after
http://marc.info/?l=linux-kernel&m=112766129313883http://secunia.com/advisories/17826http://secunia.com/advisories/17917http://secunia.com/advisories/17918http://secunia.com/advisories/19374http://secunia.com/advisories/21035http://secunia.com/advisories/21136http://secunia.com/advisories/21465http://secunia.com/advisories/21983http://secunia.com/advisories/22417http://support.avaya.com/elmodocs2/security/ASA-2006-180.htmhttp://support.avaya.com/elmodocs2/security/ASA-2006-200.htmhttp://www.debian.org/security/2006/dsa-1017http://www.mandriva.com/security/advisories?name=MDKSA-2005:218http://www.mandriva.com/security/advisories?name=MDKSA-2005:219http://www.mandriva.com/security/advisories?name=MDKSA-2005:220http://www.mandriva.com/security/advisories?name=MDKSA-2005:235http://www.redhat.com/support/errata/RHSA-2006-0437.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0575.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0579.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0580.htmlhttp://www.securityfocus.com/advisories/9806http://www.securityfocus.com/archive/1/419522/100/0/threadedhttp://www.securityfocus.com/bid/14955http://www.vupen.com/english/advisories/2005/1863https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9472https://usn.ubuntu.com/219-1/http://marc.info/?l=linux-kernel&m=112766129313883http://secunia.com/advisories/17826http://secunia.com/advisories/17917http://secunia.com/advisories/17918http://secunia.com/advisories/19374http://secunia.com/advisories/21035http://secunia.com/advisories/21136http://secunia.com/advisories/21465http://secunia.com/advisories/21983http://secunia.com/advisories/22417http://support.avaya.com/elmodocs2/security/ASA-2006-180.htmhttp://support.avaya.com/elmodocs2/security/ASA-2006-200.htmhttp://www.debian.org/security/2006/dsa-1017http://www.mandriva.com/security/advisories?name=MDKSA-2005:218http://www.mandriva.com/security/advisories?name=MDKSA-2005:219http://www.mandriva.com/security/advisories?name=MDKSA-2005:220http://www.mandriva.com/security/advisories?name=MDKSA-2005:235http://www.redhat.com/support/errata/RHSA-2006-0437.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0575.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0579.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0580.htmlhttp://www.securityfocus.com/advisories/9806http://www.securityfocus.com/archive/1/419522/100/0/threadedhttp://www.securityfocus.com/bid/14955http://www.vupen.com/english/advisories/2005/1863https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9472https://usn.ubuntu.com/219-1/
2005-09-26
Published