CVE-2015-7509
published 2015-12-28CVE-2015-7509: fs/ext4/namei.c in the Linux kernel before 3.7 allows physically proximate attackers to cause a denial of service (system crash) via a crafted no-journal…
PriorityP413medium4.4CVSS 3.0
AVLACLPRHUINSUCNINAH
EPSS
0.40%
33.6th percentile
fs/ext4/namei.c in the Linux kernel before 3.7 allows physically proximate attackers to cause a denial of service (system crash) via a crafted no-journal filesystem, a related issue to CVE-2013-2015.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.8-1~experimental.1 (bookworm) | linux 3.8-1~experimental.1 (bookworm) |
| linux | linux_kernel | <= 3.6.11 | — |
| linux | linux_kernel | >= 0 < 3.8-1~experimental.1 | 3.8-1~experimental.1 |
| linux | linux_kernel | >= 0 < 3.8-1~experimental.1 | 3.8-1~experimental.1 |
| linux | linux_kernel | >= 0 < 3.8-1~experimental.1 | 3.8-1~experimental.1 |
| linux | linux_kernel | >= 0 < 3.8-1~experimental.1 | 3.8-1~experimental.1 |
CVSS provenance
nvdv3.04.4MEDIUMCVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv4.7MEDIUM
vendor_debian4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-35m7-pw2x-j9f6: fs/ext4/namei
ghsa_unreviewed·2022-05-17·CVSS 4.7
CVE-2015-7509 [MEDIUM] CWE-20 GHSA-35m7-pw2x-j9f6: fs/ext4/namei
fs/ext4/namei.c in the Linux kernel before 3.7 allows physically proximate attackers to cause a denial of service (system crash) via a crafted no-journal filesystem, a related issue to CVE-2013-2015.
OSV
CVE-2015-7509: fs/ext4/namei
osv·2015-12-28·CVSS 4.7
CVE-2015-7509 [MEDIUM] CVE-2015-7509: fs/ext4/namei
fs/ext4/namei.c in the Linux kernel before 3.7 allows physically proximate attackers to cause a denial of service (system crash) via a crafted no-journal filesystem, a related issue to CVE-2013-2015.
Red Hat
kernel: Mounting ext2 fs e2fsprogs/tests/f_orphan as ext4 crashes system
vendor_redhat·2015-11-24·CVSS 4.7
CVE-2015-7509 [MEDIUM] CWE-250 kernel: Mounting ext2 fs e2fsprogs/tests/f_orphan as ext4 crashes system
kernel: Mounting ext2 fs e2fsprogs/tests/f_orphan as ext4 crashes system
fs/ext4/namei.c in the Linux kernel before 3.7 allows physically proximate attackers to cause a denial of service (system crash) via a crafted no-journal filesystem, a related issue to CVE-2013-2015.
A flaw was found in the way the Linux kernel's ext4 file system driver handled non-journal file systems with an orphan list. An attacker with physical access to the system could use this flaw to crash the system or, although unlikely, escalate their privileges on the system.
Statement: This problem did not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 7 and MRG-2. This issue is not planned to be corrected in future updates for Red Hat Enterprise Linux 5.
This issue is rated low as exploiting
Debian
CVE-2015-7509: linux - fs/ext4/namei.c in the Linux kernel before 3.7 allows physically proximate attac...
vendor_debian·2015·CVSS 4.7
CVE-2015-7509 [MEDIUM] CVE-2015-7509: linux - fs/ext4/namei.c in the Linux kernel before 3.7 allows physically proximate attac...
fs/ext4/namei.c in the Linux kernel before 3.7 allows physically proximate attackers to cause a denial of service (system crash) via a crafted no-journal filesystem, a related issue to CVE-2013-2015.
Scope: local
bookworm: resolved (fixed in 3.8-1~experimental.1)
bullseye: resolved (fixed in 3.8-1~experimental.1)
forky: resolved (fixed in 3.8-1~experimental.1)
sid: resolved (fixed in 3.8-1~experimental.1)
trixie: resolved (fixed in 3.8-1~experimental.1)
No detection rules found.
No public exploits indexed.
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=c9b92530a723ac5ef8e352885a1862b18f31b2f5http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00031.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00038.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0855.htmlhttp://www.securitytracker.com/id/1034559https://bugzilla.redhat.com/show_bug.cgi?id=1259222https://bugzilla.suse.com/show_bug.cgi?id=956709https://github.com/torvalds/linux/commit/c9b92530a723ac5ef8e352885a1862b18f31b2f5https://security-tracker.debian.org/tracker/CVE-2015-7509http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=c9b92530a723ac5ef8e352885a1862b18f31b2f5http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00031.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00038.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0855.htmlhttp://www.securitytracker.com/id/1034559https://bugzilla.redhat.com/show_bug.cgi?id=1259222https://bugzilla.suse.com/show_bug.cgi?id=956709https://github.com/torvalds/linux/commit/c9b92530a723ac5ef8e352885a1862b18f31b2f5https://security-tracker.debian.org/tracker/CVE-2015-7509
2015-12-28
Published