CVE-2015-8324
The ext4 implementation in the Linux kernel before 2.6.34 does not properly track the initialization of certain data structures, which allows physically proximate attackers to cause a denial of service (NULL pointer dereference and panic) via a crafted…
Does this matter?
Lower severity and a low EPSS score (0.43%). Track it; it rarely justifies an emergency change on its own.
Description
The ext4 implementation in the Linux kernel before 2.6.34 does not properly track the initialization of certain data structures, which allows physically proximate attackers to cause a denial of service (NULL pointer dereference and panic) via a crafted USB device, related to the ext4_fill_super function.
- CVSS 3.0
- 4.6 MEDIUMCVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.43% probability · 36th percentile
- CISA KEV
- Not listed
- Affected
- linux/linux kernel
- Source
- secalert@redhat.com
References
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=744692dc059845b2a3022119871846e74d4f6e11Vendor Advisory
- http://mirror.linux.org.au/linux/kernel/v2.6/ChangeLog-2.6.34
- http://rhn.redhat.com/errata/RHSA-2016-0855.html
- http://www.openwall.com/lists/oss-security/2015/11/23/2
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- https://bugzilla.redhat.com/show_bug.cgi?id=1267261
- https://github.com/torvalds/linux/commit/744692dc059845b2a3022119871846e74d4f6e11Patch, Vendor Advisory
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=744692dc059845b2a3022119871846e74d4f6e11Vendor Advisory
- http://mirror.linux.org.au/linux/kernel/v2.6/ChangeLog-2.6.34
- http://rhn.redhat.com/errata/RHSA-2016-0855.html
- http://www.openwall.com/lists/oss-security/2015/11/23/2
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- https://bugzilla.redhat.com/show_bug.cgi?id=1267261
- https://github.com/torvalds/linux/commit/744692dc059845b2a3022119871846e74d4f6e11Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.