CVE-2015-8816: Linux Kernel

Medium severity, CVSS 6.8. EPSS: 0.5% chance of exploitation in the next 30 days.

The hub_activate function in drivers/usb/core/hub.c in the Linux kernel before 4.3.5 does not properly maintain a hub-interface data structure, which allows physically proximate attackers to cause a denial of service (invalid memory access and system crash) or possibly have unspecified other impact by unplugging a USB hub device.

Affected products

  • Linux Linux Kernel: from 2.6.28, before 3.2.76 (fixed in 3.2.76); from 3.3, before 3.4.113 (fixed in 3.4.113); from 3.5, before 3.10.103 (fixed in 3.10.103); from 3.11, before 3.12.58 (fixed in 3.12.58); from 3.13, before 3.14.76 (fixed in 3.14.76); from 3.15, before 3.16.35 (fixed in 3.16.35); …
  • Novell Suse Linux Enterprise Debuginfo: version 11 only
  • Novell Suse Linux Enterprise Desktop: version 12.0 only
  • Novell Suse Linux Enterprise Live Patching: version 12.0 only
  • Novell Suse Linux Enterprise Module For Public Cloud: version 12 only
  • Novell Suse Linux Enterprise Real Time Extension: version 11 only; version 12 only
  • Novell Suse Linux Enterprise Server: version 11 only; version 12.0 only
  • Novell Suse Linux Enterprise Software Development Kit: version 11.0 only; version 12.0 only
  • Novell Suse Linux Enterprise Workstation Extension: version 12.0 only
  • Suse Linux Enterprise Live Patching: version 12 only
  • Suse Linux Enterprise Server: version 12 only

Published 2016-04-27. Last modified 2026-06-17.