CVE-2015-8816
moderate-risk
Published 2016-04-27
The hub_activate function in drivers/usb/core/hub.c in the Linux kernel before 4.3.5 does not properly maintain a hub-interface data structure, which allows physically proximate attackers to cause a denial of service (invalid memory access and system crash) or possibly have unspecified other impact by unplugging a USB hub device.
Do I need to act?
-
0.08% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
6
CVSS 6.8/10
Medium
PHYSICAL
/ LOW complexity
Affected Products (15)
References (54)
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00019.html
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00052.html
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00054.html
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00059.html
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-07/msg00005.html
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00003.html
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00008.html
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00009.html
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00015.html
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00016.html
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00018.html
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00019.html
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00020.html
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00021.html
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00022.html
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00026.html
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00038.html
Third Party Advisory
http://source.android.com/security/bulletin/2016-07-01.html
Third Party Advisory
http://www.debian.org/security/2016/dsa-3503
and 34 more references
40
/ 100
moderate-risk
Severity
22/34 · High
Exploitability
0/34 · Minimal
Exposure
18/34 · Moderate