CVE-2015-8952
The mbcache feature in the ext2 and ext4 filesystem implementations in the Linux kernel before 4.6 mishandles xattr block caching, which allows local users to cause a denial of service (soft lockup) via filesystem operations in environments that use…
Does this matter?
Lower severity and a low EPSS score (0.45%). Track it; it rarely justifies an emergency change on its own.
Description
The mbcache feature in the ext2 and ext4 filesystem implementations in the Linux kernel before 4.6 mishandles xattr block caching, which allows local users to cause a denial of service (soft lockup) via filesystem operations in environments that use many attributes, as demonstrated by Ceph and Samba.
- CVSS 3.0
- 5.5 MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.45% probability · 38th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-19
- Affected
- linux/linux kernel
- Source
- cve@mitre.org
References
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=82939d7999dfc1f1998c4b1c12e2f19edbdff272Patch
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=be0726d33cb8f411945884664924bed3cb8c70eePatch
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=f9a61eb4e2471c56a63cd804c7474128138c38acPatch
- http://www.openwall.com/lists/oss-security/2016/08/22/2Third Party Advisory
- http://www.openwall.com/lists/oss-security/2016/08/25/4Patch, Third Party Advisory
- https://bugzilla.kernel.org/show_bug.cgi?id=107301Issue Tracking, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1360968Issue Tracking, Third Party Advisory, VDB Entry
- https://github.com/torvalds/linux/commit/82939d7999dfc1f1998c4b1c12e2f19edbdff272Vendor Advisory
- https://github.com/torvalds/linux/commit/be0726d33cb8f411945884664924bed3cb8c70eeIssue Tracking, Patch
- https://github.com/torvalds/linux/commit/f9a61eb4e2471c56a63cd804c7474128138c38acIssue Tracking
- https://lwn.net/Articles/668718/Third Party Advisory
- https://usn.ubuntu.com/3582-1/
- https://usn.ubuntu.com/3582-2/
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=82939d7999dfc1f1998c4b1c12e2f19edbdff272Patch
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=be0726d33cb8f411945884664924bed3cb8c70eePatch
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=f9a61eb4e2471c56a63cd804c7474128138c38acPatch
- http://www.openwall.com/lists/oss-security/2016/08/22/2Third Party Advisory
- http://www.openwall.com/lists/oss-security/2016/08/25/4Patch, Third Party Advisory
- https://bugzilla.kernel.org/show_bug.cgi?id=107301Issue Tracking, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1360968Issue Tracking, Third Party Advisory, VDB Entry
- https://github.com/torvalds/linux/commit/82939d7999dfc1f1998c4b1c12e2f19edbdff272Vendor Advisory
- https://github.com/torvalds/linux/commit/be0726d33cb8f411945884664924bed3cb8c70eeIssue Tracking, Patch
- https://github.com/torvalds/linux/commit/f9a61eb4e2471c56a63cd804c7474128138c38acIssue Tracking
- https://lwn.net/Articles/668718/Third Party Advisory
- https://usn.ubuntu.com/3582-1/
- https://usn.ubuntu.com/3582-2/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.