CVE-2015-8961: Linux Kernel
High severity, CVSS 7.8. EPSS: 2% chance of exploitation in the next 30 days.
The __ext4_journal_stop function in fs/ext4/ext4_jbd2.c in the Linux kernel before 4.3.3 allows local users to gain privileges or cause a denial of service (use-after-free) by leveraging improper access to a certain error field.
Affected products
- Linux Linux Kernel: from 3.10.85, before 3.12 (fixed in 3.12); from 3.12.46, before 3.12.52 (fixed in 3.12.52); from 3.14.49, before 3.14.59 (fixed in 3.14.59); from 3.18.20, before 3.18.54 (fixed in 3.18.54); from 4.1.4, before 4.1.15 (fixed in 4.1.15); from 4.2, before 4.2.8 (fixed in 4.2.8); …
Published 2016-11-16. Last modified 2026-06-17.