CVE-2015-8952
published 2016-10-16CVE-2015-8952: The mbcache feature in the ext2 and ext4 filesystem implementations in the Linux kernel before 4.6 mishandles xattr block caching, which allows local users to…
PriorityP419medium5.5CVSS 3.0
AVLACLPRLUINSUCNINAH
EPSS
0.45%
37.2th percentile
The mbcache feature in the ext2 and ext4 filesystem implementations in the Linux kernel before 4.6 mishandles xattr block caching, which allows local users to cause a denial of service (soft lockup) via filesystem operations in environments that use many attributes, as demonstrated by Ceph and Samba.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.6.1-1 (bookworm) | linux 4.6.1-1 (bookworm) |
| linux | linux_kernel | <= 4.5.7 | — |
| linux | linux_kernel | >= 0 < 4.6.1-1 | 4.6.1-1 |
| linux | linux_kernel | >= 0 < 4.6.1-1 | 4.6.1-1 |
| linux | linux_kernel | >= 0 < 4.6.1-1 | 4.6.1-1 |
| linux | linux_kernel | >= 0 < 4.6.1-1 | 4.6.1-1 |
| linux | linux_kernel | >= 0 < 4.4.0-116.140 | 4.4.0-116.140 |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r248-wpg2-5hw4: The mbcache feature in the ext2 and ext4 filesystem implementations in the Linux kernel before 4
ghsa_unreviewed·2022-05-14
CVE-2015-8952 [MEDIUM] GHSA-r248-wpg2-5hw4: The mbcache feature in the ext2 and ext4 filesystem implementations in the Linux kernel before 4
The mbcache feature in the ext2 and ext4 filesystem implementations in the Linux kernel before 4.6 mishandles xattr block caching, which allows local users to cause a denial of service (soft lockup) via filesystem operations in environments that use many attributes, as demonstrated by Ceph and Samba.
OSV
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
osv·2018-02-22·CVSS 5.5
CVE-2017-17712 [MEDIUM] linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
Mohamed Ghannam discovered that the IPv4 raw socket implementation in the
Linux kernel contained a race condition leading to uninitialized pointer
usage. A local attacker could use this to cause a denial of service or
possibly execute arbitrary code. (CVE-2017-17712)
Laurent Guerby discovered that the mbcache feature in the ext2 and ext4
filesystems in the Linux kernel improperly handled xattr block caching. A
local attacker could use this to cause a denial of service. (CVE-2015-8952)
Vitaly Mayatskikh discovered that the SCSI subsystem in the Linux kernel
did not properly track reference counts when merging buffers. A local
attacker could use this to cause a denial of service (memory exhaustion).
(CVE-2017-1219
OSV
linux-lts-xenial, linux-aws vulnerabilities
osv·2018-02-22·CVSS 5.5
[MEDIUM] linux-lts-xenial, linux-aws vulnerabilities
linux-lts-xenial, linux-aws vulnerabilities
USN-3582-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
Mohamed Ghannam discovered that the IPv4 raw socket implementation in the
Linux kernel contained a race condition leading to uninitialized pointer
usage. A local attacker could use this to cause a denial of service or
possibly execute arbitrary code. (CVE-2017-17712)
Laurent Guerby discovered that the mbcache feature in the ext2 and ext4
filesystems in the Linux kernel improperly handled xattr block caching. A
local attacker could use this to cause a denial of service. (CVE-2015-8952)
Vitaly Mayatskikh discovered that the SCSI subsys
OSV
CVE-2015-8952: The mbcache feature in the ext2 and ext4 filesystem implementations in the Linux kernel before 4
osv·2016-10-16·CVSS 5.5
CVE-2015-8952 [MEDIUM] CVE-2015-8952: The mbcache feature in the ext2 and ext4 filesystem implementations in the Linux kernel before 4
The mbcache feature in the ext2 and ext4 filesystem implementations in the Linux kernel before 4.6 mishandles xattr block caching, which allows local users to cause a denial of service (soft lockup) via filesystem operations in environments that use many attributes, as demonstrated by Ceph and Samba.
Ubuntu
Linux kernel (Xenial HWE) vulnerabilities
vendor_ubuntu·2018-02-22·CVSS 5.5
CVE-2015-8952 [MEDIUM] Linux kernel (Xenial HWE) vulnerabilities
Title: Linux kernel (Xenial HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3582-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
Mohamed Ghannam discovered that the IPv4 raw socket implementation in the
Linux kernel contained a race condition leading to uninitialized pointer
usage. A local attacker could use this to cause a denial of service or
possibly execute arbitrary code. (CVE-2017-17712)
Laurent Guerby discovered that the mbcache feature in the ext2 and ext4
filesystems in the Linux kernel improperly handled xattr block caching. A
local attacker could use this to cause a denial of serv
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2018-02-22·CVSS 5.5
CVE-2015-8952 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Mohamed Ghannam discovered that the IPv4 raw socket implementation in the
Linux kernel contained a race condition leading to uninitialized pointer
usage. A local attacker could use this to cause a denial of service or
possibly execute arbitrary code. (CVE-2017-17712)
Laurent Guerby discovered that the mbcache feature in the ext2 and ext4
filesystems in the Linux kernel improperly handled xattr block caching. A
local attacker could use this to cause a denial of service. (CVE-2015-8952)
Vitaly Mayatskikh discovered that the SCSI subsystem in the Linux kernel
did not properly track reference counts when merging buffers. A local
attacker could use this to cause a denial of service (memory e
Red Hat
kernel: mbcache code subject to softlockup DOS in cache management
vendor_redhat·2016-08-22·CVSS 5.5
CVE-2015-8952 [MEDIUM] CWE-667 kernel: mbcache code subject to softlockup DOS in cache management
kernel: mbcache code subject to softlockup DOS in cache management
The mbcache feature in the ext2 and ext4 filesystem implementations in the Linux kernel before 4.6 mishandles xattr block caching, which allows local users to cause a denial of service (soft lockup) via filesystem operations in environments that use many attributes, as demonstrated by Ceph and Samba.
A design flaw was found in the file extended attribute handling of the Linux kernel's handling of cached attributes. Too many entries in the cache cause a soft lockup while attempting to iterate the cache and access relevant locks.
Statement: This issue does not affect any shiping version of Red Hat Enterprise Linux.
Package: kernel (Red Hat Enterprise Linux 5) - Will not fix
Package: kernel (Red Hat Enterprise Linux 6) -
Debian
CVE-2015-8952: linux - The mbcache feature in the ext2 and ext4 filesystem implementations in the Linux...
vendor_debian·2015·CVSS 5.5
CVE-2015-8952 [MEDIUM] CVE-2015-8952: linux - The mbcache feature in the ext2 and ext4 filesystem implementations in the Linux...
The mbcache feature in the ext2 and ext4 filesystem implementations in the Linux kernel before 4.6 mishandles xattr block caching, which allows local users to cause a denial of service (soft lockup) via filesystem operations in environments that use many attributes, as demonstrated by Ceph and Samba.
Scope: local
bookworm: resolved (fixed in 4.6.1-1)
bullseye: resolved (fixed in 4.6.1-1)
forky: resolved (fixed in 4.6.1-1)
sid: resolved (fixed in 4.6.1-1)
trixie: resolved (fixed in 4.6.1-1)
No detection rules found.
No public exploits indexed.
arXiv
The Security War in File Systems: An Empirical Study from A Vulnerability-Centric Perspective
arxiv_fulltext·2022-04-26
The Security War in File Systems: An Empirical Study from A Vulnerability-Centric Perspective
The Security War in File Systems: An Empirical Study from A Vulnerability-Centric Perspective
## Abstract
This paper presents a systematic study on the security of modern file systems,
following a vulnerability-centric perspective. Specifically,
we collected 377 file system vulnerabilities committed to the CVE database in the past 20 years.
We characterize them from four dimensions that include why the vulnerabilities appear,
how the vulnerabilities can be exploited, what consequences can arise,
and how the vulnerabilities are fixed. This way, we build a deep understanding of
the attack surfaces faced by file systems, the threats imposed by the attack surfaces,
and the good and bad practices in mitigating the attacks in file systems. We envision that our study
will bring insights toward
arXiv
SPI: Automated Identification of Security Patches via Commits
arxiv_fulltext·2021-06-06
SPI: Automated Identification of Security Patches via Commits
SPI: Automated Identification of Security Patches via Commits
Yaqin Zhou
indicate equal contribution
[email protected]
Nanyang Technological University
Singapore
Jing Kai Siow
[1]
Nanyang Technological University
Singapore
[email protected]
Chenyu Wang
Nanyang Technological University
Singapore
[email protected]
Shangqing Liu
Nanyang Technological University
Singapore
[email protected]
Yang Liu
Nanyang Technological University
Singapore
[email protected]
## Abstract
Security patches in open-source software, providing security fixes to identified vulnerabilities, are crucial in protecting against cyber attacks. Security advisories and announcements are often publicly released to inform the users about potential security vulnerability. Despite the National Vul
Bugzilla
CVE-2015-8952 kernel: mbcache code subject to softlockup DOS in cache management [fedora-all]
bugzilla·2016-08-22·CVSS 5.5
CVE-2015-8952 [MEDIUM] CVE-2015-8952 kernel: mbcache code subject to softlockup DOS in cache management [fedora-all]
CVE-2015-8952 kernel: mbcache code subject to softlockup DOS in cache management [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple suppor
Bugzilla
CVE-2015-8952 kernel: mbcache code subject to softlockup DOS in cache management
bugzilla·2016-07-28·CVSS 5.5
CVE-2015-8952 [MEDIUM] CVE-2015-8952 kernel: mbcache code subject to softlockup DOS in cache management
CVE-2015-8952 kernel: mbcache code subject to softlockup DOS in cache management
A design flaw was found in the file extended attribute handling of the linux kernels handling of cached attributes. Too many entries in the cache cause a soft lockup while attempting to iterate the cache and access relevant locks.
Upstream has replaced the mbcache code with an updated version which was not a patch but a clear-cut reimplentation of the code.
Upstream discussion:
https://lwn.net/Articles/668718/
Bugzilla kernel submission:
https://bugzilla.kernel.org/show_bug.cgi?id=107301
Probable fix:
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=be0726d33cb8f411945884664924bed3cb8c70ee
Discussion:
Acknowledgements:
Red Hat would like to thank Laurent Guerby for bringing th
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=82939d7999dfc1f1998c4b1c12e2f19edbdff272http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=be0726d33cb8f411945884664924bed3cb8c70eehttp://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=f9a61eb4e2471c56a63cd804c7474128138c38achttp://www.openwall.com/lists/oss-security/2016/08/22/2http://www.openwall.com/lists/oss-security/2016/08/25/4https://bugzilla.kernel.org/show_bug.cgi?id=107301https://bugzilla.redhat.com/show_bug.cgi?id=1360968https://github.com/torvalds/linux/commit/82939d7999dfc1f1998c4b1c12e2f19edbdff272https://github.com/torvalds/linux/commit/be0726d33cb8f411945884664924bed3cb8c70eehttps://github.com/torvalds/linux/commit/f9a61eb4e2471c56a63cd804c7474128138c38achttps://lwn.net/Articles/668718/https://usn.ubuntu.com/3582-1/https://usn.ubuntu.com/3582-2/http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=82939d7999dfc1f1998c4b1c12e2f19edbdff272http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=be0726d33cb8f411945884664924bed3cb8c70eehttp://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=f9a61eb4e2471c56a63cd804c7474128138c38achttp://www.openwall.com/lists/oss-security/2016/08/22/2http://www.openwall.com/lists/oss-security/2016/08/25/4https://bugzilla.kernel.org/show_bug.cgi?id=107301https://bugzilla.redhat.com/show_bug.cgi?id=1360968https://github.com/torvalds/linux/commit/82939d7999dfc1f1998c4b1c12e2f19edbdff272https://github.com/torvalds/linux/commit/be0726d33cb8f411945884664924bed3cb8c70eehttps://github.com/torvalds/linux/commit/f9a61eb4e2471c56a63cd804c7474128138c38achttps://lwn.net/Articles/668718/https://usn.ubuntu.com/3582-1/https://usn.ubuntu.com/3582-2/
2016-10-16
Published