LiveActive security incident?Get immediate response
CVE Record

CVE-2015-8816: The hub_activate function in drivers/usb/core/hub.c in the Linux kernel before 4.3.5 does not properly main...

The hub_activate function in drivers/usb/core/hub.c in the Linux kernel before 4.3.5 does not properly maintain a hub-interface data structure, which allows physically proximate attackers to cause a denial of service (invalid memory access and system crash) or possibly have unspecified other impact by unplugging a USB hub device.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysis

Security readout for executives and security teams

CVE-2015-8816 is a Linux kernel USB hub bug that can let someone with physical access crash a system by unplugging a USB hub. The public record does not show active exploitation or a CVSS score. Business urgency is highest for systems where untrusted people can reach USB ports. Exposure is limited to Linux systems running vulnerable kernel code before 4.3.5 or vendor kernels without the backported fix. Real risk depends on distro patch status and whether attackers can physically access USB hub connections. Prioritize remediation for exposed physical-access environments, but this is not a typical internet-facing emergency. Patch through normal kernel maintenance unless public USB access or safety-critical availability makes system crashes materially disruptive. Mitigation focus: Update to a kernel or vendor package containing the hub_activate fix.; Check Debian, SUSE, Oracle, Android, or relevant vendor advisories for backported packages.; Restrict untrusted physical access to USB ports where patching is delayed..

Prepared

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2015-8816 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
3Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.