// For flags

CVE-2015-8816

 

Severity Score

6.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The hub_activate function in drivers/usb/core/hub.c in the Linux kernel before 4.3.5 does not properly maintain a hub-interface data structure, which allows physically proximate attackers to cause a denial of service (invalid memory access and system crash) or possibly have unspecified other impact by unplugging a USB hub device.

La función hub_activate en drivers/usb/core/hub.c en el Kernel de Linux en versiones anteriores a 4.3.5 no mantiene correctamente una estructura de datos hub-interface, lo que permite a atacantes físicamente próximos provocar una denegación de servicio (acceso a memoria no válido y caída de sistema) o posiblemente tener otro impacto no especificado desenchufando un dispositivo hub USB.

*Credits: N/A
CVSS Scores
Attack Vector
Physical
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2016-02-23 CVE Reserved
  • 2016-03-04 CVE Published
  • 2023-11-10 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
CAPEC
References (27)
URL Date SRC
URL Date SRC
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=e50293ef9775c5f1cf3fcc093037dd6a8c5684ea 2023-11-01
http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00019.html 2023-11-01
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00052.html 2023-11-01
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00054.html 2023-11-01
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00059.html 2023-11-01
http://lists.opensuse.org/opensuse-security-announce/2016-07/msg00005.html 2023-11-01
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00003.html 2023-11-01
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00008.html 2023-11-01
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00009.html 2023-11-01
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00015.html 2023-11-01
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00016.html 2023-11-01
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00018.html 2023-11-01
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00019.html 2023-11-01
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00020.html 2023-11-01
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00021.html 2023-11-01
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00022.html 2023-11-01
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00026.html 2023-11-01
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00038.html 2023-11-01
http://www.debian.org/security/2016/dsa-3503 2023-11-01
http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.3.5 2023-11-01
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Novell
Search vendor "Novell"
Suse Linux Enterprise Software Development Kit
Search vendor "Novell" for product "Suse Linux Enterprise Software Development Kit"
11.0
Search vendor "Novell" for product "Suse Linux Enterprise Software Development Kit" and version "11.0"
sp4
Affected
Novell
Search vendor "Novell"
Suse Linux Enterprise Software Development Kit
Search vendor "Novell" for product "Suse Linux Enterprise Software Development Kit"
12.0
Search vendor "Novell" for product "Suse Linux Enterprise Software Development Kit" and version "12.0"
-
Affected
Novell
Search vendor "Novell"
Suse Linux Enterprise Debuginfo
Search vendor "Novell" for product "Suse Linux Enterprise Debuginfo"
11
Search vendor "Novell" for product "Suse Linux Enterprise Debuginfo" and version "11"
sp4
Affected
Novell
Search vendor "Novell"
Suse Linux Enterprise Desktop
Search vendor "Novell" for product "Suse Linux Enterprise Desktop"
12.0
Search vendor "Novell" for product "Suse Linux Enterprise Desktop" and version "12.0"
-
Affected
Novell
Search vendor "Novell"
Suse Linux Enterprise Live Patching
Search vendor "Novell" for product "Suse Linux Enterprise Live Patching"
12.0
Search vendor "Novell" for product "Suse Linux Enterprise Live Patching" and version "12.0"
-
Affected
Novell
Search vendor "Novell"
Suse Linux Enterprise Module For Public Cloud
Search vendor "Novell" for product "Suse Linux Enterprise Module For Public Cloud"
12
Search vendor "Novell" for product "Suse Linux Enterprise Module For Public Cloud" and version "12"
-
Affected
Novell
Search vendor "Novell"
Suse Linux Enterprise Real Time Extension
Search vendor "Novell" for product "Suse Linux Enterprise Real Time Extension"
11
Search vendor "Novell" for product "Suse Linux Enterprise Real Time Extension" and version "11"
sp4
Affected
Novell
Search vendor "Novell"
Suse Linux Enterprise Real Time Extension
Search vendor "Novell" for product "Suse Linux Enterprise Real Time Extension"
12
Search vendor "Novell" for product "Suse Linux Enterprise Real Time Extension" and version "12"
sp1
Affected
Novell
Search vendor "Novell"
Suse Linux Enterprise Server
Search vendor "Novell" for product "Suse Linux Enterprise Server"
11
Search vendor "Novell" for product "Suse Linux Enterprise Server" and version "11"
extra
Affected
Novell
Search vendor "Novell"
Suse Linux Enterprise Server
Search vendor "Novell" for product "Suse Linux Enterprise Server"
11
Search vendor "Novell" for product "Suse Linux Enterprise Server" and version "11"
sp4
Affected
Novell
Search vendor "Novell"
Suse Linux Enterprise Server
Search vendor "Novell" for product "Suse Linux Enterprise Server"
12.0
Search vendor "Novell" for product "Suse Linux Enterprise Server" and version "12.0"
-
Affected
Novell
Search vendor "Novell"
Suse Linux Enterprise Workstation Extension
Search vendor "Novell" for product "Suse Linux Enterprise Workstation Extension"
12.0
Search vendor "Novell" for product "Suse Linux Enterprise Workstation Extension" and version "12.0"
-
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
>= 2.6.28 < 3.2.76
Search vendor "Linux" for product "Linux Kernel" and version " >= 2.6.28 < 3.2.76"
-
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
>= 3.3 < 3.4.113
Search vendor "Linux" for product "Linux Kernel" and version " >= 3.3 < 3.4.113"
-
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
>= 3.5 < 3.10.103
Search vendor "Linux" for product "Linux Kernel" and version " >= 3.5 < 3.10.103"
-
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
>= 3.11 < 3.12.58
Search vendor "Linux" for product "Linux Kernel" and version " >= 3.11 < 3.12.58"
-
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
>= 3.13 < 3.14.76
Search vendor "Linux" for product "Linux Kernel" and version " >= 3.13 < 3.14.76"
-
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
>= 3.15 < 3.16.35
Search vendor "Linux" for product "Linux Kernel" and version " >= 3.15 < 3.16.35"
-
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
>= 3.17 < 3.18.27
Search vendor "Linux" for product "Linux Kernel" and version " >= 3.17 < 3.18.27"
-
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
>= 3.19 < 4.1.17
Search vendor "Linux" for product "Linux Kernel" and version " >= 3.19 < 4.1.17"
-
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
>= 4.2 < 4.3.5
Search vendor "Linux" for product "Linux Kernel" and version " >= 4.2 < 4.3.5"
-
Affected
Suse
Search vendor "Suse"
Linux Enterprise Live Patching
Search vendor "Suse" for product "Linux Enterprise Live Patching"
12
Search vendor "Suse" for product "Linux Enterprise Live Patching" and version "12"
-
Affected
Suse
Search vendor "Suse"
Linux Enterprise Server
Search vendor "Suse" for product "Linux Enterprise Server"
12
Search vendor "Suse" for product "Linux Enterprise Server" and version "12"
ltss
Affected