CVE-2015-8324
published 2016-05-02CVE-2015-8324: The ext4 implementation in the Linux kernel before 2.6.34 does not properly track the initialization of certain data structures, which allows physically…
PriorityP414medium4.6CVSS 3.0
AVPACLPRNUINSUCNINAH
EPSS
0.43%
35.4th percentile
The ext4 implementation in the Linux kernel before 2.6.34 does not properly track the initialization of certain data structures, which allows physically proximate attackers to cause a denial of service (NULL pointer dereference and panic) via a crafted USB device, related to the ext4_fill_super function.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 2.6.37-1 (bookworm) | linux 2.6.37-1 (bookworm) |
| linux | linux_kernel | <= 2.6.33.20 | — |
| linux | linux_kernel | >= 0 < 2.6.37-1 | 2.6.37-1 |
| linux | linux_kernel | >= 0 < 2.6.37-1 | 2.6.37-1 |
| linux | linux_kernel | >= 0 < 2.6.37-1 | 2.6.37-1 |
| linux | linux_kernel | >= 0 < 2.6.37-1 | 2.6.37-1 |
CVSS provenance
nvdv3.04.6MEDIUMCVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv4.6MEDIUM
vendor_debian4.6MEDIUM
vendor_redhat4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: Null pointer dereference when mounting ext4
vendor_redhat·2015-11-23·CVSS 4.6
CVE-2015-8324 [MEDIUM] CWE-476 kernel: Null pointer dereference when mounting ext4
kernel: Null pointer dereference when mounting ext4
The ext4 implementation in the Linux kernel before 2.6.34 does not properly track the initialization of certain data structures, which allows physically proximate attackers to cause a denial of service (NULL pointer dereference and panic) via a crafted USB device, related to the ext4_fill_super function.
A NULL pointer dereference flaw was found in the way the Linux kernel's ext4 file system driver handled certain corrupted file system images. An attacker with physical access to the system could use this flaw to crash the system.
Statement: This problem did not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 5, 7 and MRG-2.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat
Debian
CVE-2015-8324: linux - The ext4 implementation in the Linux kernel before 2.6.34 does not properly trac...
vendor_debian·2015·CVSS 4.6
CVE-2015-8324 [MEDIUM] CVE-2015-8324: linux - The ext4 implementation in the Linux kernel before 2.6.34 does not properly trac...
The ext4 implementation in the Linux kernel before 2.6.34 does not properly track the initialization of certain data structures, which allows physically proximate attackers to cause a denial of service (NULL pointer dereference and panic) via a crafted USB device, related to the ext4_fill_super function.
Scope: local
bookworm: resolved (fixed in 2.6.37-1)
bullseye: resolved (fixed in 2.6.37-1)
forky: resolved (fixed in 2.6.37-1)
sid: resolved (fixed in 2.6.37-1)
trixie: resolved (fixed in 2.6.37-1)
GHSA
GHSA-f6x7-vppw-cjgq: The ext4 implementation in the Linux kernel before 2
ghsa_unreviewed·2022-05-17
CVE-2015-8324 [MEDIUM] GHSA-f6x7-vppw-cjgq: The ext4 implementation in the Linux kernel before 2
The ext4 implementation in the Linux kernel before 2.6.34 does not properly track the initialization of certain data structures, which allows physically proximate attackers to cause a denial of service (NULL pointer dereference and panic) via a crafted USB device, related to the ext4_fill_super function.
OSV
CVE-2015-8324: The ext4 implementation in the Linux kernel before 2
osv·2016-05-02·CVSS 4.6
CVE-2015-8324 [MEDIUM] CVE-2015-8324: The ext4 implementation in the Linux kernel before 2
The ext4 implementation in the Linux kernel before 2.6.34 does not properly track the initialization of certain data structures, which allows physically proximate attackers to cause a denial of service (NULL pointer dereference and panic) via a crafted USB device, related to the ext4_fill_super function.
No detection rules found.
No public exploits indexed.
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=744692dc059845b2a3022119871846e74d4f6e11http://mirror.linux.org.au/linux/kernel/v2.6/ChangeLog-2.6.34http://rhn.redhat.com/errata/RHSA-2016-0855.htmlhttp://www.openwall.com/lists/oss-security/2015/11/23/2http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1267261https://github.com/torvalds/linux/commit/744692dc059845b2a3022119871846e74d4f6e11http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=744692dc059845b2a3022119871846e74d4f6e11http://mirror.linux.org.au/linux/kernel/v2.6/ChangeLog-2.6.34http://rhn.redhat.com/errata/RHSA-2016-0855.htmlhttp://www.openwall.com/lists/oss-security/2015/11/23/2http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1267261https://github.com/torvalds/linux/commit/744692dc059845b2a3022119871846e74d4f6e11
2016-05-02
Published