CVE-2015-8816
published 2016-04-27CVE-2015-8816: The hub_activate function in drivers/usb/core/hub.c in the Linux kernel before 4.3.5 does not properly maintain a hub-interface data structure, which allows…
PriorityP424medium6.8CVSS 3.1
AVPACLPRNUINSUCHIHAH
EPSS
0.54%
42.0th percentile
The hub_activate function in drivers/usb/core/hub.c in the Linux kernel before 4.3.5 does not properly maintain a hub-interface data structure, which allows physically proximate attackers to cause a denial of service (invalid memory access and system crash) or possibly have unspecified other impact by unplugging a USB hub device.
Affected
28 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.4.2-1 (bookworm) | linux 4.4.2-1 (bookworm) |
| android | — | — | |
| linux | linux_kernel | >= 0 < 4.4.2-1 | 4.4.2-1 |
| linux | linux_kernel | >= 0 < 4.4.2-1 | 4.4.2-1 |
| linux | linux_kernel | >= 0 < 4.4.2-1 | 4.4.2-1 |
| linux | linux_kernel | >= 0 < 4.4.2-1 | 4.4.2-1 |
| linux | linux_kernel | >= 2.6.28 < 3.2.76 | 3.2.76 |
| linux | linux_kernel | >= 3.11 < 3.12.58 | 3.12.58 |
| linux | linux_kernel | >= 3.13 < 3.14.76 | 3.14.76 |
| linux | linux_kernel | >= 3.15 < 3.16.35 | 3.16.35 |
| linux | linux_kernel | >= 3.17 < 3.18.27 | 3.18.27 |
| linux | linux_kernel | >= 3.19 < 4.1.17 | 4.1.17 |
| linux | linux_kernel | >= 3.3 < 3.4.113 | 3.4.113 |
| linux | linux_kernel | >= 3.5 < 3.10.103 | 3.10.103 |
| linux | linux_kernel | >= 4.2 < 4.3.5 | 4.3.5 |
| novell | suse_linux_enterprise_debuginfo | — | — |
| novell | suse_linux_enterprise_desktop | — | — |
| novell | suse_linux_enterprise_live_patching | — | — |
| novell | suse_linux_enterprise_module_for_public_cloud | — | — |
| novell | suse_linux_enterprise_real_time_extension | — | — |
| novell | suse_linux_enterprise_real_time_extension | — | — |
| novell | suse_linux_enterprise_server | — | — |
| novell | suse_linux_enterprise_server | — | — |
| novell | suse_linux_enterprise_software_development_kit | — | — |
| novell | suse_linux_enterprise_software_development_kit | — | — |
CVSS provenance
nvdv3.16.8MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2015-8816: Android Security Bulletin 2016-07-01
CVE: CVE-2015-8816
Severity: CRITICAL
References: A-28712303*
vendor_android·2016-07-01·CVSS 6.8
CVE-2015-8816 [MEDIUM] CVE-2015-8816: Android Security Bulletin 2016-07-01
CVE: CVE-2015-8816
Severity: CRITICAL
References: A-28712303*
Android Security Bulletin 2016-07-01
CVE: CVE-2015-8816
Severity: CRITICAL
References: A-28712303*
Red Hat
kernel: USB hub invalid memory access in hub_activate()
vendor_redhat·2016-02-23·CVSS 6.8
CVE-2015-8816 [MEDIUM] CWE-476 kernel: USB hub invalid memory access in hub_activate()
kernel: USB hub invalid memory access in hub_activate()
The hub_activate function in drivers/usb/core/hub.c in the Linux kernel before 4.3.5 does not properly maintain a hub-interface data structure, which allows physically proximate attackers to cause a denial of service (invalid memory access and system crash) or possibly have unspecified other impact by unplugging a USB hub device.
Statement: This issue does not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 5 as the code with the flaw is not present in the products listed.
This issue affects the Linux kernel packages as shipped with Red Hat Enterprise Linux 6, 7, and Red Hat Enterprise MRG 2. This has been rated as having Low security impact and is not currently planned to be addressed in future updates. Fo
Debian
CVE-2015-8816: linux - The hub_activate function in drivers/usb/core/hub.c in the Linux kernel before 4...
vendor_debian·2015·CVSS 6.8
CVE-2015-8816 [MEDIUM] CVE-2015-8816: linux - The hub_activate function in drivers/usb/core/hub.c in the Linux kernel before 4...
The hub_activate function in drivers/usb/core/hub.c in the Linux kernel before 4.3.5 does not properly maintain a hub-interface data structure, which allows physically proximate attackers to cause a denial of service (invalid memory access and system crash) or possibly have unspecified other impact by unplugging a USB hub device.
Scope: local
bookworm: resolved (fixed in 4.4.2-1)
bullseye: resolved (fixed in 4.4.2-1)
forky: resolved (fixed in 4.4.2-1)
sid: resolved (fixed in 4.4.2-1)
trixie: resolved (fixed in 4.4.2-1)
GHSA
GHSA-9h4c-rfpq-mrp2: The hub_activate function in drivers/usb/core/hub
ghsa_unreviewed·2022-05-17
CVE-2015-8816 [HIGH] GHSA-9h4c-rfpq-mrp2: The hub_activate function in drivers/usb/core/hub
The hub_activate function in drivers/usb/core/hub.c in the Linux kernel before 4.3.5 does not properly maintain a hub-interface data structure, which allows physically proximate attackers to cause a denial of service (invalid memory access and system crash) or possibly have unspecified other impact by unplugging a USB hub device.
OSV
CVE-2015-8816: The hub_activate function in drivers/usb/core/hub
osv·2016-04-27·CVSS 6.8
CVE-2015-8816 [MEDIUM] CVE-2015-8816: The hub_activate function in drivers/usb/core/hub
The hub_activate function in drivers/usb/core/hub.c in the Linux kernel before 4.3.5 does not properly maintain a hub-interface data structure, which allows physically proximate attackers to cause a denial of service (invalid memory access and system crash) or possibly have unspecified other impact by unplugging a USB hub device.
No detection rules found.
No public exploits indexed.
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=e50293ef9775c5f1cf3fcc093037dd6a8c5684eahttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00019.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00052.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00054.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00059.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-07/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00016.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00019.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00022.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00038.htmlhttp://source.android.com/security/bulletin/2016-07-01.htmlhttp://www.debian.org/security/2016/dsa-3503http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.3.5http://www.openwall.com/lists/oss-security/2016/02/23/5http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinoct2016-3090547.htmlhttp://www.securityfocus.com/bid/83363https://bugzilla.redhat.com/show_bug.cgi?id=1311589https://github.com/torvalds/linux/commit/e50293ef9775c5f1cf3fcc093037dd6a8c5684eahttp://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=e50293ef9775c5f1cf3fcc093037dd6a8c5684eahttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00019.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00052.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00054.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00059.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-07/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00016.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00019.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00022.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00038.htmlhttp://source.android.com/security/bulletin/2016-07-01.htmlhttp://www.debian.org/security/2016/dsa-3503http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.3.5http://www.openwall.com/lists/oss-security/2016/02/23/5http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinoct2016-3090547.htmlhttp://www.securityfocus.com/bid/83363https://bugzilla.redhat.com/show_bug.cgi?id=1311589https://github.com/torvalds/linux/commit/e50293ef9775c5f1cf3fcc093037dd6a8c5684ea
2016-04-27
Published