Denial of Service Vulnerability in Linux Kernel USB Hub Functionality
CVE-2015-8816

6.8MEDIUM

What is CVE-2015-8816?

The hub_activate function within the Linux kernel, prior to version 4.3.5, is vulnerable due to improper management of hub-interface data structures. This flaw allows attackers located in close physical proximity to exploit the vulnerability by unplugging a USB hub device. Such action can lead to invalid memory access, resulting in potential system crashes and denial of service. This vulnerability underscores the importance of maintaining robust security measures for USB interfaces in Linux-based systems.

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.