CVE-2015-8961
published 2016-11-16CVE-2015-8961: The __ext4_journal_stop function in fs/ext4/ext4_jbd2.c in the Linux kernel before 4.3.3 allows local users to gain privileges or cause a denial of service…
PriorityP337high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
2.00%
78.8th percentile
The __ext4_journal_stop function in fs/ext4/ext4_jbd2.c in the Linux kernel before 4.3.3 allows local users to gain privileges or cause a denial of service (use-after-free) by leveraging improper access to a certain error field.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.3.3-1 (bookworm) | linux 4.3.3-1 (bookworm) |
| android | — | — | |
| linux | linux_kernel | >= 0 < 4.3.3-1 | 4.3.3-1 |
| linux | linux_kernel | >= 0 < 4.3.3-1 | 4.3.3-1 |
| linux | linux_kernel | >= 0 < 4.3.3-1 | 4.3.3-1 |
| linux | linux_kernel | >= 0 < 4.3.3-1 | 4.3.3-1 |
| linux | linux_kernel | >= 3.10.85 < 3.12 | 3.12 |
| linux | linux_kernel | >= 3.12.46 < 3.12.52 | 3.12.52 |
| linux | linux_kernel | >= 3.14.49 < 3.14.59 | 3.14.59 |
| linux | linux_kernel | >= 3.18.20 < 3.18.54 | 3.18.54 |
| linux | linux_kernel | >= 4.1.4 < 4.1.15 | 4.1.15 |
| linux | linux_kernel | >= 4.2 < 4.2.8 | 4.2.8 |
| linux | linux_kernel | >= 4.3 < 4.3.3 | 4.3.3 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-66r4-mrh6-vw83: The __ext4_journal_stop function in fs/ext4/ext4_jbd2
ghsa_unreviewed·2022-05-17
CVE-2015-8961 [HIGH] CWE-416 GHSA-66r4-mrh6-vw83: The __ext4_journal_stop function in fs/ext4/ext4_jbd2
The __ext4_journal_stop function in fs/ext4/ext4_jbd2.c in the Linux kernel before 4.3.3 allows local users to gain privileges or cause a denial of service (use-after-free) by leveraging improper access to a certain error field.
OSV
CVE-2015-8961: The __ext4_journal_stop function in fs/ext4/ext4_jbd2
osv·2016-11-16·CVSS 7.8
CVE-2015-8961 [HIGH] CVE-2015-8961: The __ext4_journal_stop function in fs/ext4/ext4_jbd2
The __ext4_journal_stop function in fs/ext4/ext4_jbd2.c in the Linux kernel before 4.3.3 allows local users to gain privileges or cause a denial of service (use-after-free) by leveraging improper access to a certain error field.
Android
CVE-2015-8961: Android Security Bulletin 2016-11-01
CVE: CVE-2015-8961
Severity: CRITICAL
References: A-30952474
Upstream
kernel
vendor_android·2016-11-01·CVSS 7.8
CVE-2015-8961 [HIGH] CVE-2015-8961: Android Security Bulletin 2016-11-01
CVE: CVE-2015-8961
Severity: CRITICAL
References: A-30952474
Upstream
kernel
Android Security Bulletin 2016-11-01
CVE: CVE-2015-8961
Severity: CRITICAL
References: A-30952474
Upstream
kernel
Red Hat
kernel: Use after free in __ext4_journal_stop
vendor_redhat·2015-10-18·CVSS 7.8
CVE-2015-8961 [HIGH] CWE-416 kernel: Use after free in __ext4_journal_stop
kernel: Use after free in __ext4_journal_stop
The __ext4_journal_stop function in fs/ext4/ext4_jbd2.c in the Linux kernel before 4.3.3 allows local users to gain privileges or cause a denial of service (use-after-free) by leveraging improper access to a certain error field.
A flaw was found in the ext4 subsystem. This vulnerability is a use after free vulnerability was found in __ext4_journal_stop(). Attackers could abuse this to allow any code which attempts to deal with the journal failure to be mishandled or not fail at all. This could lead to data corruption or crashes.
Statement: This issue does not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 5, 6, 7 and MRG 2.x. This issue has been rated as having moderate security impact.
Package: kernel (Red Hat En
Debian
CVE-2015-8961: linux - The __ext4_journal_stop function in fs/ext4/ext4_jbd2.c in the Linux kernel befo...
vendor_debian·2015·CVSS 7.8
CVE-2015-8961 [HIGH] CVE-2015-8961: linux - The __ext4_journal_stop function in fs/ext4/ext4_jbd2.c in the Linux kernel befo...
The __ext4_journal_stop function in fs/ext4/ext4_jbd2.c in the Linux kernel before 4.3.3 allows local users to gain privileges or cause a denial of service (use-after-free) by leveraging improper access to a certain error field.
Scope: local
bookworm: resolved (fixed in 4.3.3-1)
bullseye: resolved (fixed in 4.3.3-1)
forky: resolved (fixed in 4.3.3-1)
sid: resolved (fixed in 4.3.3-1)
trixie: resolved (fixed in 4.3.3-1)
No detection rules found.
No public exploits indexed.
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=6934da9238da947628be83635e365df41064b09bhttp://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.3.3http://www.securityfocus.com/bid/94135https://github.com/torvalds/linux/commit/6934da9238da947628be83635e365df41064b09bhttps://source.android.com/security/bulletin/2016-11-01.htmlhttp://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=6934da9238da947628be83635e365df41064b09bhttp://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.3.3http://www.securityfocus.com/bid/94135https://github.com/torvalds/linux/commit/6934da9238da947628be83635e365df41064b09bhttps://source.android.com/security/bulletin/2016-11-01.html
2016-11-16
Published