MEDIUM · 6.8

CVE-2015-8816

The hub_activate function in drivers/usb/core/hub.c in the Linux kernel before 4.3.5 does not properly maintain a hub-interface data structure, which allows physically proximate attackers to cause a d...

Vulnerability Description

The hub_activate function in drivers/usb/core/hub.c in the Linux kernel before 4.3.5 does not properly maintain a hub-interface data structure, which allows physically proximate attackers to cause a denial of service (invalid memory access and system crash) or possibly have unspecified other impact by unplugging a USB hub device.

CVSS Score

6.8

MEDIUM

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
PHYSICAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
NovellSuse Linux Enterprise Software Development Kit11.0
NovellSuse Linux Enterprise Debuginfo11
NovellSuse Linux Enterprise Desktop12.0
NovellSuse Linux Enterprise Live Patching12.0
NovellSuse Linux Enterprise Module For Public Cloud12
NovellSuse Linux Enterprise Real Time Extension11
NovellSuse Linux Enterprise Server11
NovellSuse Linux Enterprise Workstation Extension12.0
LinuxLinux Kernel>= 2.6.28, < 3.2.76
SuseLinux Enterprise Live Patching12
SuseLinux Enterprise Server12

References

FAQ

What is CVE-2015-8816?

CVE-2015-8816 is a vulnerability with a CVSS score of 6.8 (MEDIUM). The hub_activate function in drivers/usb/core/hub.c in the Linux kernel before 4.3.5 does not properly maintain a hub-interface data structure, which allows physically proximate attackers to cause a d...

How severe is CVE-2015-8816?

CVE-2015-8816 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-8816?

Check the references section above for vendor advisories and patch information. Affected products include: Novell Suse Linux Enterprise Software Development Kit, Novell Suse Linux Enterprise Debuginfo, Novell Suse Linux Enterprise Desktop, Novell Suse Linux Enterprise Live Patching, Novell Suse Linux Enterprise Module For Public Cloud.