Vulnerability Description
The ext4 implementation in the Linux kernel before 2.6.34 does not properly track the initialization of certain data structures, which allows physically proximate attackers to cause a denial of service (NULL pointer dereference and panic) via a crafted USB device, related to the ext4_fill_super function.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | <= 2.6.33.20 |
References
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=744692Vendor Advisory
- http://mirror.linux.org.au/linux/kernel/v2.6/ChangeLog-2.6.34
- http://rhn.redhat.com/errata/RHSA-2016-0855.html
- http://www.openwall.com/lists/oss-security/2015/11/23/2
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.h
- https://bugzilla.redhat.com/show_bug.cgi?id=1267261
- https://github.com/torvalds/linux/commit/744692dc059845b2a3022119871846e74d4f6e1PatchVendor Advisory
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=744692Vendor Advisory
- http://mirror.linux.org.au/linux/kernel/v2.6/ChangeLog-2.6.34
- http://rhn.redhat.com/errata/RHSA-2016-0855.html
- http://www.openwall.com/lists/oss-security/2015/11/23/2
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.h
- https://bugzilla.redhat.com/show_bug.cgi?id=1267261
- https://github.com/torvalds/linux/commit/744692dc059845b2a3022119871846e74d4f6e1PatchVendor Advisory
FAQ
What is CVE-2015-8324?
CVE-2015-8324 is a vulnerability with a CVSS score of 4.6 (MEDIUM). The ext4 implementation in the Linux kernel before 2.6.34 does not properly track the initialization of certain data structures, which allows physically proximate attackers to cause a denial of servic...
How severe is CVE-2015-8324?
CVE-2015-8324 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-8324?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.