cbcvebase.
CVE-2015-8816
published 2016-04-27

CVE-2015-8816: The hub_activate function in drivers/usb/core/hub.c in the Linux kernel before 4.3.5 does not properly maintain a hub-interface data structure, which allows…

medium6.8CVSS 3.1
AVPACLPRNUINSUCHIHAH
The hub_activate function in drivers/usb/core/hub.c in the Linux kernel before 4.3.5 does not properly maintain a hub-interface data structure, which allows physically proximate attackers to cause a denial of service (invalid memory access and system crash) or possibly have unspecified other impact by unplugging a USB hub device.

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 4.4.2-1 (bookworm)linux 4.4.2-1 (bookworm)
googleandroid
linuxlinux_kernel>= 0 < 4.4.2-14.4.2-1
linuxlinux_kernel>= 0 < 4.4.2-14.4.2-1
linuxlinux_kernel>= 0 < 4.4.2-14.4.2-1
linuxlinux_kernel>= 0 < 4.4.2-14.4.2-1
linuxlinux_kernel>= 2.6.28 < 3.2.763.2.76
linuxlinux_kernel>= 3.11 < 3.12.583.12.58
linuxlinux_kernel>= 3.13 < 3.14.763.14.76
linuxlinux_kernel>= 3.15 < 3.16.353.16.35
linuxlinux_kernel>= 3.17 < 3.18.273.18.27
linuxlinux_kernel>= 3.19 < 4.1.174.1.17
linuxlinux_kernel>= 3.3 < 3.4.1133.4.113
linuxlinux_kernel>= 3.5 < 3.10.1033.10.103
linuxlinux_kernel>= 4.2 < 4.3.54.3.5
novellsuse_linux_enterprise_debuginfo
novellsuse_linux_enterprise_desktop
novellsuse_linux_enterprise_live_patching
novellsuse_linux_enterprise_module_for_public_cloud
novellsuse_linux_enterprise_real_time_extension
novellsuse_linux_enterprise_real_time_extension
novellsuse_linux_enterprise_server
novellsuse_linux_enterprise_server
novellsuse_linux_enterprise_software_development_kit
novellsuse_linux_enterprise_software_development_kit

CVSS provenance

nvdv3.16.8MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv6.8MEDIUM