The hub_activate function in drivers/usb/core/hub.c in the Linux kernel before 4.3.5 does not properly maintain a hub-interface data structure, which allows physically proximate attackers to cause a denial of service (invalid memory access and system crash) or possibly have unspecified other impact by unplugging a USB hub device.

Project Subscriptions

Vendors Products
Linux Kernel Subscribe
Suse Linux Enterprise Debuginfo Subscribe
Suse Linux Enterprise Desktop Subscribe
Suse Linux Enterprise Live Patching Subscribe
Suse Linux Enterprise Module For Public Cloud Subscribe
Suse Linux Enterprise Real Time Extension Subscribe
Suse Linux Enterprise Server Subscribe
Suse Linux Enterprise Software Development Kit Subscribe
Suse Linux Enterprise Workstation Extension Subscribe
Linux Enterprise Live Patching Subscribe
Linux Enterprise Server Subscribe
Advisories
Source ID Title
Debian DSA Debian DSA DSA-3503-1 linux security update
EUVD EUVD EUVD-2015-8682 The hub_activate function in drivers/usb/core/hub.c in the Linux kernel before 4.3.5 does not properly maintain a hub-interface data structure, which allows physically proximate attackers to cause a denial of service (invalid memory access and system crash) or possibly have unspecified other impact by unplugging a USB hub device.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
Link Providers
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=e50293ef9775c5f1cf3fcc093037dd6a8c5684ea cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00019.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00052.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00054.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00059.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2016-07/msg00005.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00003.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00008.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00009.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00015.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00016.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00018.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00019.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00020.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00021.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00022.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00026.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00038.html cve-icon cve-icon
http://source.android.com/security/bulletin/2016-07-01.html cve-icon cve-icon
http://www.debian.org/security/2016/dsa-3503 cve-icon cve-icon
http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.3.5 cve-icon cve-icon
http://www.openwall.com/lists/oss-security/2016/02/23/5 cve-icon cve-icon
http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html cve-icon cve-icon
http://www.oracle.com/technetwork/topics/security/ovmbulletinoct2016-3090547.html cve-icon cve-icon
http://www.securityfocus.com/bid/83363 cve-icon cve-icon
http://www.spinics.net/lists/linux-usb/msg132311.html cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=1311589 cve-icon cve-icon
https://github.com/torvalds/linux/commit/e50293ef9775c5f1cf3fcc093037dd6a8c5684ea cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2015-8816 cve-icon
https://www.cve.org/CVERecord?id=CVE-2015-8816 cve-icon
History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-06T08:29:22.034Z

Reserved: 2016-02-23T00:00:00

Link: CVE-2015-8816

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2016-04-27T17:59:03.147

Modified: 2025-04-12T10:46:40.837

Link: CVE-2015-8816

cve-icon Redhat

Severity : Low

Publid Date: 2016-02-23T00:00:00Z

Links: CVE-2015-8816 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses