CVE-2015-8952
Last modified
CVE-2015-8952 is a vulnerability of currently unknown severity. The mbcache feature in the ext2 and ext4 filesystem implementations in the Linux kernel before 4.6 mishandles xattr block caching, which allows local users to cause a denial of service (soft lockup) via filesystem operations in environments that use many attributes, as demonstrated by Ceph and Samba.. EPSS estimates a 0.45% chance of exploitation in the next 30 days.
Description
The mbcache feature in the ext2 and ext4 filesystem implementations in the Linux kernel before 4.6 mishandles xattr block caching, which allows local users to cause a denial of service (soft lockup) via filesystem operations in environments that use many attributes, as demonstrated by Ceph and Samba.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | <= 4.5.7 |
References
- http://www.openwall.com/lists/oss-security/2016/08/22/2Third Party Advisory
- http://www.openwall.com/lists/oss-security/2016/08/25/4Patch, Third Party Advisory
- https://bugzilla.kernel.org/show_bug.cgi?id=107301Issue Tracking, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1360968Issue Tracking, Third Party Advisory, VDB Entry
- https://github.com/torvalds/linux/commit/be0726d33cb8f411945884664924bed3cb8c70eeIssue Tracking, Patch
- https://lwn.net/Articles/668718/Third Party Advisory
- http://www.openwall.com/lists/oss-security/2016/08/22/2Third Party Advisory
- http://www.openwall.com/lists/oss-security/2016/08/25/4Patch, Third Party Advisory
- https://bugzilla.kernel.org/show_bug.cgi?id=107301Issue Tracking, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1360968Issue Tracking, Third Party Advisory, VDB Entry
- https://github.com/torvalds/linux/commit/be0726d33cb8f411945884664924bed3cb8c70eeIssue Tracking, Patch
- https://lwn.net/Articles/668718/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-8952?
How severe is CVE-2015-8952?
How do I fix CVE-2015-8952?
Are you affected by CVE-2015-8952?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
