Description
The hub_activate function in drivers/usb/core/hub.c in the Linux kernel before 4.3.5 does not properly maintain a hub-interface data structure, which allows physically proximate attackers to cause a denial of service (invalid memory access and system crash) or possibly have unspecified other impact by unplugging a USB hub device.
Published: 2016-04-27
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-3503-1 linux security update
EUVD EUVD EUVD-2015-8682 The hub_activate function in drivers/usb/core/hub.c in the Linux kernel before 4.3.5 does not properly maintain a hub-interface data structure, which allows physically proximate attackers to cause a denial of service (invalid memory access and system crash) or possibly have unspecified other impact by unplugging a USB hub device.
References
Link Providers
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=e50293ef9775c5f1cf3fcc093037dd6a8c5684ea cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00019.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00052.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00054.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00059.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2016-07/msg00005.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00003.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00008.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00009.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00015.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00016.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00018.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00019.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00020.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00021.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00022.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00026.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00038.html cve-icon cve-icon
http://source.android.com/security/bulletin/2016-07-01.html cve-icon cve-icon
http://www.debian.org/security/2016/dsa-3503 cve-icon cve-icon
http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.3.5 cve-icon cve-icon
http://www.openwall.com/lists/oss-security/2016/02/23/5 cve-icon cve-icon
http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html cve-icon cve-icon
http://www.oracle.com/technetwork/topics/security/ovmbulletinoct2016-3090547.html cve-icon cve-icon
http://www.securityfocus.com/bid/83363 cve-icon cve-icon
http://www.spinics.net/lists/linux-usb/msg132311.html cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=1311589 cve-icon cve-icon
https://github.com/torvalds/linux/commit/e50293ef9775c5f1cf3fcc093037dd6a8c5684ea cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2015-8816 cve-icon
https://www.cve.org/CVERecord?id=CVE-2015-8816 cve-icon
History

No history.

Subscriptions

Linux Linux Kernel
Novell Suse Linux Enterprise Debuginfo Suse Linux Enterprise Desktop Suse Linux Enterprise Live Patching Suse Linux Enterprise Module For Public Cloud Suse Linux Enterprise Real Time Extension Suse Linux Enterprise Server Suse Linux Enterprise Software Development Kit Suse Linux Enterprise Workstation Extension
Suse Linux Enterprise Live Patching Linux Enterprise Server
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-06T08:29:22.034Z

Reserved: 2016-02-23T00:00:00.000Z

Link: CVE-2015-8816

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2016-04-27T17:59:03.147

Modified: 2025-04-12T10:46:40.837

Link: CVE-2015-8816

cve-icon Redhat

Severity : Low

Publid Date: 2016-02-23T00:00:00Z

Links: CVE-2015-8816 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses