CVE-2015-7833
published 2015-10-19CVE-2015-7833: The usbvision driver in the Linux kernel package 3.10.0-123.20.1.el7 through 3.10.0-229.14.1.el7 in Red Hat Enterprise Linux (RHEL) 7.1 allows physically…
PriorityP417medium4.9CVSS 2.0
AVLACLAuNCNINAC
EPSS
0.68%
48.1th percentile
The usbvision driver in the Linux kernel package 3.10.0-123.20.1.el7 through 3.10.0-229.14.1.el7 in Red Hat Enterprise Linux (RHEL) 7.1 allows physically proximate attackers to cause a denial of service (panic) via a nonzero bInterfaceNumber value in a USB device descriptor.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.2.6-2 (bookworm) | linux 4.2.6-2 (bookworm) |
| linux | linux_kernel | >= 0 < 4.2.6-2 | 4.2.6-2 |
| linux | linux_kernel | >= 0 < 4.2.6-2 | 4.2.6-2 |
| linux | linux_kernel | >= 0 < 4.2.6-2 | 4.2.6-2 |
| linux | linux_kernel | >= 0 < 4.2.6-2 | 4.2.6-2 |
| linux | linux_kernel | >= 0 < 3.13.0-83.127 | 3.13.0-83.127 |
| novell | suse_linux_enterprise_real_time_extension | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv6.2MEDIUM
vendor_ubuntu6.2MEDIUM
vendor_debian4.9MEDIUM
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2016-05-09·CVSS 6.2
CVE-2013-4312 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that the Linux kernel did not properly enforce rlimits
for file descriptors sent over UNIX domain sockets. A local attacker could
use this to cause a denial of service. (CVE-2013-4312)
Ralf Spenneberg discovered that the Aiptek Tablet USB device driver in the
Linux kernel did not properly validate the endpoints reported by the
device. An attacker with physical access could cause a denial of service
(system crash). (CVE-2015-7515)
Ralf Spenneberg discovered that the USB driver for Clie devices in the
Linux kernel did not properly validate the endpoints reported by the
device. An attacker with physical access could cause a denial of service
(system crash). (CVE-2015-7566)
Ral
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2016-05-09·CVSS 6.2
CVE-2013-4312 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that the Linux kernel did not properly enforce rlimits
for file descriptors sent over UNIX domain sockets. A local attacker could
use this to cause a denial of service. (CVE-2013-4312)
Ralf Spenneberg discovered that the Aiptek Tablet USB device driver in the
Linux kernel did not properly validate the endpoints reported by the
device. An attacker with physical access could cause a denial of service
(system crash). (CVE-2015-7515)
Ralf Spenneberg discovered that the USB driver for Clie devices in the
Linux kernel did not properly validate the endpoints reported by the
device. An attacker with physical access could cause a denial of service
(system crash). (CVE-2015-75
Ubuntu
Linux kernel (Utopic HWE) regression
vendor_ubuntu·2016-04-11·CVSS 4.6
[MEDIUM] Linux kernel (Utopic HWE) regression
Title: Linux kernel (Utopic HWE) regression
Summary: USN 2948-1 introduced a regression in the Ubuntu 14.10 Linux kernel
backported to Ubuntu 14.04 LTS.
USN-2948-1 fixed vulnerabilities in the Ubuntu 14.10 Linux kernel
backported to Ubuntu 14.04 LTS. An incorrect reference counting
fix in the radeon driver introduced a regression that could cause a
system crash. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Ralf Spenneberg discovered that the USB driver for Clie devices in the
Linux kernel did not properly validate the endpoints reported by the
device. An attacker with physical access could cause a denial of service
(system crash). (CVE-2015-7566)
Ralf Spenneberg discovered that the usbvision driver in the Linux kernel
did not properly
Ubuntu
Linux kernel (Wily HWE) vulnerabilities
vendor_ubuntu·2016-04-06·CVSS 4.9
CVE-2015-7833 [MEDIUM] Linux kernel (Wily HWE) vulnerabilities
Title: Linux kernel (Wily HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Ralf Spenneberg discovered that the usbvision driver in the Linux kernel
did not properly validate the interfaces and endpoints reported by the
device. An attacker with physical access could cause a denial of service
(system crash). (CVE-2015-7833)
Venkatesh Pottem discovered a use-after-free vulnerability in the Linux
kernel's CXGB3 driver. A local attacker could use this to cause a denial of
service (system crash) or possibly execute arbitrary code. (CVE-2015-8812)
Xiaofei Rex Guo discovered a timing side channel vulnerability in the Linux
Extended Verification Module (EVM). An attacker could use this to affect
system integrity. (CVE-2016-2085)
It was discovered that the extende
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2016-04-06·CVSS 4.9
CVE-2015-7833 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Ralf Spenneberg discovered that the usbvision driver in the Linux kernel
did not properly validate the interfaces and endpoints reported by the
device. An attacker with physical access could cause a denial of service
(system crash). (CVE-2015-7833)
Venkatesh Pottem discovered a use-after-free vulnerability in the Linux
kernel's CXGB3 driver. A local attacker could use this to cause a denial of
service (system crash) or possibly execute arbitrary code. (CVE-2015-8812)
Xiaofei Rex Guo discovered a timing side channel vulnerability in the Linux
Extended Verification Module (EVM). An attacker could use this to affect
system integrity. (CVE-2016-2085)
It was discovered that the extended Berkeley
Ubuntu
Linux kernel (Raspberry Pi 2) vulnerabilities
vendor_ubuntu·2016-04-06·CVSS 4.9
CVE-2015-7833 [MEDIUM] Linux kernel (Raspberry Pi 2) vulnerabilities
Title: Linux kernel (Raspberry Pi 2) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Ralf Spenneberg discovered that the usbvision driver in the Linux kernel
did not properly validate the interfaces and endpoints reported by the
device. An attacker with physical access could cause a denial of service
(system crash). (CVE-2015-7833)
Venkatesh Pottem discovered a use-after-free vulnerability in the Linux
kernel's CXGB3 driver. A local attacker could use this to cause a denial of
service (system crash) or possibly execute arbitrary code. (CVE-2015-8812)
Xiaofei Rex Guo discovered a timing side channel vulnerability in the Linux
Extended Verification Module (EVM). An attacker could use this to affect
system integrity. (CVE-2016-2085)
It was discovered that the e
Ubuntu
Linux kernel (Utopic HWE) vulnerabilities
vendor_ubuntu·2016-04-06·CVSS 4.6
CVE-2015-7566 [MEDIUM] Linux kernel (Utopic HWE) vulnerabilities
Title: Linux kernel (Utopic HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Ralf Spenneberg discovered that the USB driver for Clie devices in the
Linux kernel did not properly validate the endpoints reported by the
device. An attacker with physical access could cause a denial of service
(system crash). (CVE-2015-7566)
Ralf Spenneberg discovered that the usbvision driver in the Linux kernel
did not properly validate the interfaces and endpoints reported by the
device. An attacker with physical access could cause a denial of service
(system crash). (CVE-2015-7833)
Venkatesh Pottem discovered a use-after-free vulnerability in the Linux
kernel's CXGB3 driver. A local attacker could use this to cause a denial of
service (system crash) or possibly execute arb
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2016-03-14·CVSS 6.2
CVE-2013-4312 [MEDIUM] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Ben Hawkes discovered that the Linux netfilter implementation did not
correctly perform validation when handling IPT_SO_SET_REPLACE events. A
local unprivileged attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code with administrative
privileges. (CVE-2016-3134)
It was discovered that the Linux kernel did not properly enforce rlimits
for file descriptors sent over UNIX domain sockets. A local attacker could
use this to cause a denial of service. (CVE-2013-4312)
Ralf Spenneberg discovered that the USB driver for Clie devices in the
Linux kernel did not properly validate the endpoints reported by the
device. An attacker with physical
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2016-03-14·CVSS 6.2
CVE-2013-4312 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Ben Hawkes discovered that the Linux netfilter implementation did not
correctly perform validation when handling IPT_SO_SET_REPLACE events. A
local unprivileged attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code with administrative
privileges. (CVE-2016-3134)
It was discovered that the Linux kernel did not properly enforce rlimits
for file descriptors sent over UNIX domain sockets. A local attacker could
use this to cause a denial of service. (CVE-2013-4312)
Ralf Spenneberg discovered that the USB driver for Clie devices in the
Linux kernel did not properly validate the endpoints reported by the
device. An attacker with physical access could
Ubuntu
Linux kernel (Vivid HWE) vulnerabilities
vendor_ubuntu·2016-03-14·CVSS 6.2
CVE-2013-4312 [MEDIUM] Linux kernel (Vivid HWE) vulnerabilities
Title: Linux kernel (Vivid HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Ben Hawkes discovered that the Linux netfilter implementation did not
correctly perform validation when handling IPT_SO_SET_REPLACE events. A
local unprivileged attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code with administrative
privileges. (CVE-2016-3134)
It was discovered that the Linux kernel did not properly enforce rlimits
for file descriptors sent over UNIX domain sockets. A local attacker could
use this to cause a denial of service. (CVE-2013-4312)
Ralf Spenneberg discovered that the USB driver for Clie devices in the
Linux kernel did not properly validate the endpoints reported by the
device. An attacker with physical
Red Hat
kernel: usbvision: crash on invalid USB device descriptors
vendor_redhat·2015-10-08·CVSS 4.9
CVE-2015-7833 [MEDIUM] CWE-476 kernel: usbvision: crash on invalid USB device descriptors
kernel: usbvision: crash on invalid USB device descriptors
The usbvision driver in the Linux kernel package 3.10.0-123.20.1.el7 through 3.10.0-229.14.1.el7 in Red Hat Enterprise Linux (RHEL) 7.1 allows physically proximate attackers to cause a denial of service (panic) via a nonzero bInterfaceNumber value in a USB device descriptor.
An out-of-bounds memory access flaw was found in the USBVision USB camera driver (usbvision_probe() function in drivers/media/usb/usbvision/usbvision-video.c). The driver assumes that the interfaces numbers of the USB device are always in 0,1,2,3... order. By using a specially crafted USB device which advertises an out-of-order number on one of its interfaces, an unprivileged user with physical access to the system can trigger a kernel NULL-pointer dereferenc
Debian
CVE-2015-7833: linux - The usbvision driver in the Linux kernel package 3.10.0-123.20.1.el7 through 3.1...
vendor_debian·2015·CVSS 4.9
CVE-2015-7833 [MEDIUM] CVE-2015-7833: linux - The usbvision driver in the Linux kernel package 3.10.0-123.20.1.el7 through 3.1...
The usbvision driver in the Linux kernel package 3.10.0-123.20.1.el7 through 3.10.0-229.14.1.el7 in Red Hat Enterprise Linux (RHEL) 7.1 allows physically proximate attackers to cause a denial of service (panic) via a nonzero bInterfaceNumber value in a USB device descriptor.
Scope: local
bookworm: resolved (fixed in 4.2.6-2)
bullseye: resolved (fixed in 4.2.6-2)
forky: resolved (fixed in 4.2.6-2)
sid: resolved (fixed in 4.2.6-2)
trixie: resolved (fixed in 4.2.6-2)
GHSA
GHSA-w2rm-wmhp-cvj7: The usbvision driver in the Linux kernel package 3
ghsa_unreviewed·2022-05-17
CVE-2015-7833 [MEDIUM] GHSA-w2rm-wmhp-cvj7: The usbvision driver in the Linux kernel package 3
The usbvision driver in the Linux kernel package 3.10.0-123.20.1.el7 through 3.10.0-229.14.1.el7 in Red Hat Enterprise Linux (RHEL) 7.1 allows physically proximate attackers to cause a denial of service (panic) via a nonzero bInterfaceNumber value in a USB device descriptor.
OSV
linux-lts-utopic regression
osv·2016-04-11·CVSS 4.6
[MEDIUM] linux-lts-utopic regression
linux-lts-utopic regression
USN-2948-1 fixed vulnerabilities in the Ubuntu 14.10 Linux kernel
backported to Ubuntu 14.04 LTS. An incorrect reference counting
fix in the radeon driver introduced a regression that could cause a
system crash. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Ralf Spenneberg discovered that the USB driver for Clie devices in the
Linux kernel did not properly validate the endpoints reported by the
device. An attacker with physical access could cause a denial of service
(system crash). (CVE-2015-7566)
Ralf Spenneberg discovered that the usbvision driver in the Linux kernel
did not properly validate the interfaces and endpoints reported by the
device. An attacker with physical access could cause a denial of service
OSV
linux-lts-utopic vulnerabilities
osv·2016-04-06·CVSS 4.6
CVE-2015-7566 [MEDIUM] linux-lts-utopic vulnerabilities
linux-lts-utopic vulnerabilities
Ralf Spenneberg discovered that the USB driver for Clie devices in the
Linux kernel did not properly validate the endpoints reported by the
device. An attacker with physical access could cause a denial of service
(system crash). (CVE-2015-7566)
Ralf Spenneberg discovered that the usbvision driver in the Linux kernel
did not properly validate the interfaces and endpoints reported by the
device. An attacker with physical access could cause a denial of service
(system crash). (CVE-2015-7833)
Venkatesh Pottem discovered a use-after-free vulnerability in the Linux
kernel's CXGB3 driver. A local attacker could use this to cause a denial of
service (system crash) or possibly execute arbitrary code. (CVE-2015-8812)
It was discovered that a race condition existe
OSV
linux-lts-wily vulnerabilities
osv·2016-04-06·CVSS 4.9
CVE-2015-7833 [MEDIUM] linux-lts-wily vulnerabilities
linux-lts-wily vulnerabilities
Ralf Spenneberg discovered that the usbvision driver in the Linux kernel
did not properly validate the interfaces and endpoints reported by the
device. An attacker with physical access could cause a denial of service
(system crash). (CVE-2015-7833)
Venkatesh Pottem discovered a use-after-free vulnerability in the Linux
kernel's CXGB3 driver. A local attacker could use this to cause a denial of
service (system crash) or possibly execute arbitrary code. (CVE-2015-8812)
Xiaofei Rex Guo discovered a timing side channel vulnerability in the Linux
Extended Verification Module (EVM). An attacker could use this to affect
system integrity. (CVE-2016-2085)
It was discovered that the extended Berkeley Packet Filter (eBPF)
implementation in the Linux kernel did not c
OSV
linux-lts-vivid vulnerabilities
osv·2016-03-14·CVSS 6.2
CVE-2016-3134 [MEDIUM] linux-lts-vivid vulnerabilities
linux-lts-vivid vulnerabilities
Ben Hawkes discovered that the Linux netfilter implementation did not
correctly perform validation when handling IPT_SO_SET_REPLACE events. A
local unprivileged attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code with administrative
privileges. (CVE-2016-3134)
It was discovered that the Linux kernel did not properly enforce rlimits
for file descriptors sent over UNIX domain sockets. A local attacker could
use this to cause a denial of service. (CVE-2013-4312)
Ralf Spenneberg discovered that the USB driver for Clie devices in the
Linux kernel did not properly validate the endpoints reported by the
device. An attacker with physical access could cause a denial of service
(system crash). (CVE-2015-7566)
Ralf
OSV
linux vulnerabilities
osv·2016-03-14·CVSS 6.2
CVE-2016-3134 [MEDIUM] linux vulnerabilities
linux vulnerabilities
Ben Hawkes discovered that the Linux netfilter implementation did not
correctly perform validation when handling IPT_SO_SET_REPLACE events. A
local unprivileged attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code with administrative
privileges. (CVE-2016-3134)
It was discovered that the Linux kernel did not properly enforce rlimits
for file descriptors sent over UNIX domain sockets. A local attacker could
use this to cause a denial of service. (CVE-2013-4312)
Ralf Spenneberg discovered that the USB driver for Clie devices in the
Linux kernel did not properly validate the endpoints reported by the
device. An attacker with physical access could cause a denial of service
(system crash). (CVE-2015-7566)
Ralf Spenneber
OSV
CVE-2015-7833: The usbvision driver in the Linux kernel package 3
osv·2015-10-19·CVSS 4.9
CVE-2015-7833 [MEDIUM] CVE-2015-7833: The usbvision driver in the Linux kernel package 3
The usbvision driver in the Linux kernel package 3.10.0-123.20.1.el7 through 3.10.0-229.14.1.el7 in Red Hat Enterprise Linux (RHEL) 7.1 allows physically proximate attackers to cause a denial of service (panic) via a nonzero bInterfaceNumber value in a USB device descriptor.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-7833 kernel: usbvision: crash on invalid USB device descriptors
bugzilla·2015-10-09·CVSS 4.9
CVE-2015-7833 [MEDIUM] CVE-2015-7833 kernel: usbvision: crash on invalid USB device descriptors
CVE-2015-7833 kernel: usbvision: crash on invalid USB device descriptors
An out-of-bounds memory access flaw was found in USBVision USB Camera Driver in usbvision_probe() function in drivers/media/usb/usbvision/usbvision-video.c. The driver assumes that the interfaces numbers of the USB device are always in 0,1,2,3... order. By using a specially crafted USB device which advertises out-of-order number on one of its interfaces an unprivileged user with a physical access can trigger a kernel NULL pointer dereference causing the system to freeze.
Acknowledgements:
Red Hat would like to thank Ralf Spenneberg of OpenSource Security for reporting this issue.
References:
Disclosure post: http://seclists.org/bugtraq/2015/Oct/35
Proposed patch: http://git.linuxtv.org/cgit.cgi/media_tree.git/co
Bugzilla
CVE-2015-7833 kernel: usbvision: crash on invalid USB device descriptors [fedora-all]
bugzilla·2015-10-09·CVSS 4.9
CVE-2015-7833 [MEDIUM] CVE-2015-7833 kernel: usbvision: crash on invalid USB device descriptors [fedora-all]
CVE-2015-7833 kernel: usbvision: crash on invalid USB device descriptors [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported vers
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00044.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00055.htmlhttp://www.debian.org/security/2015/dsa-3396http://www.debian.org/security/2015/dsa-3426http://www.os-s.net/advisories/DOS-KernelCrashesOnInvalidUSBDeviceDescriptors-UsbvisionDriver.pdfhttp://www.securityfocus.com/archive/1/536629http://www.securityfocus.com/bid/77030http://www.securitytracker.com/id/1034452http://www.ubuntu.com/usn/USN-2929-1http://www.ubuntu.com/usn/USN-2929-2http://www.ubuntu.com/usn/USN-2932-1http://www.ubuntu.com/usn/USN-2947-1http://www.ubuntu.com/usn/USN-2947-2http://www.ubuntu.com/usn/USN-2947-3http://www.ubuntu.com/usn/USN-2948-1http://www.ubuntu.com/usn/USN-2948-2http://www.ubuntu.com/usn/USN-2967-1http://www.ubuntu.com/usn/USN-2967-2https://bugzilla.redhat.com/show_bug.cgi?id=1201858http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00044.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00055.htmlhttp://www.debian.org/security/2015/dsa-3396http://www.debian.org/security/2015/dsa-3426http://www.os-s.net/advisories/DOS-KernelCrashesOnInvalidUSBDeviceDescriptors-UsbvisionDriver.pdfhttp://www.securityfocus.com/archive/1/536629http://www.securityfocus.com/bid/77030http://www.securitytracker.com/id/1034452http://www.ubuntu.com/usn/USN-2929-1http://www.ubuntu.com/usn/USN-2929-2http://www.ubuntu.com/usn/USN-2932-1http://www.ubuntu.com/usn/USN-2947-1http://www.ubuntu.com/usn/USN-2947-2http://www.ubuntu.com/usn/USN-2947-3http://www.ubuntu.com/usn/USN-2948-1http://www.ubuntu.com/usn/USN-2948-2http://www.ubuntu.com/usn/USN-2967-1http://www.ubuntu.com/usn/USN-2967-2https://bugzilla.redhat.com/show_bug.cgi?id=1201858
2015-10-19
Published