First published: Wed Feb 24 2016(Updated: )
Quickly plugging in and unplugging a USB hub can lead to a null pointer dereference in kernel (local denial of service) or the USB port to which the hub is connected becomes unusable, for kernel versions 2.6.32 < 4.4. The issue occurs when the USB hub gets disconnected before or while the routine for USB hub activation is running - hub_activate() function. Upstream patch: <a href="https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=e50293ef9775c5">https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=e50293ef9775c5</a> External references: <a href="http://www.spinics.net/lists/linux-usb/msg132311.html">http://www.spinics.net/lists/linux-usb/msg132311.html</a> CVE-ID request and assignment: <a href="http://seclists.org/oss-sec/2016/q1/404">http://seclists.org/oss-sec/2016/q1/404</a> <a href="http://seclists.org/oss-sec/2016/q1/413">http://seclists.org/oss-sec/2016/q1/413</a>
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Novell Suse Linux Enterprise Software Development Kit | =11.0-sp4 | |
Novell Suse Linux Enterprise Software Development Kit | =12.0 | |
Novell Suse Linux Enterprise Debuginfo | =11-sp4 | |
Novell Suse Linux Enterprise Desktop | =12.0 | |
Novell Suse Linux Enterprise Live Patching | =12.0 | |
Novell Suse Linux Enterprise Module For Public Cloud | =12 | |
Novell Suse Linux Enterprise Real Time Extension | =11-sp4 | |
Novell Suse Linux Enterprise Real Time Extension | =12-sp1 | |
Novell Suse Linux Enterprise Server | =11-extra | |
Novell Suse Linux Enterprise Server | =11-sp4 | |
Novell Suse Linux Enterprise Server | =12.0 | |
Novell Suse Linux Enterprise Workstation Extension | =12.0 | |
Linux Linux kernel | <=4.3.4 | |
Linux Linux kernel | >=2.6.28<3.2.76 | |
Linux Linux kernel | >=3.3<3.4.113 | |
Linux Linux kernel | >=3.5<3.10.103 | |
Linux Linux kernel | >=3.11<3.12.58 | |
Linux Linux kernel | >=3.13<3.14.76 | |
Linux Linux kernel | >=3.15<3.16.35 | |
Linux Linux kernel | >=3.17<3.18.27 | |
Linux Linux kernel | >=3.19<4.1.17 | |
Linux Linux kernel | >=4.2<4.3.5 | |
Suse Linux Enterprise Live Patching | =12 | |
SUSE Linux Enterprise Server | =12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.