cbcvebase.
CVE-2016-2782
published 2016-04-27

CVE-2016-2782: The treo_attach function in drivers/usb/serial/visor.c in the Linux kernel before 4.5 allows physically proximate attackers to cause a denial of service (NULL…

medium4.6CVSS 3.1
AVPACLPRNUINSUCNINAH
EXPLOIT
The treo_attach function in drivers/usb/serial/visor.c in the Linux kernel before 4.5 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by inserting a USB device that lacks a (1) bulk-in or (2) interrupt-in endpoint.

Affected

18 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 4.4.2-1 (bookworm)linux 4.4.2-1 (bookworm)
linuxlinux_kernel< 4.5.04.5.0
linuxlinux_kernel
linuxlinux_kernel>= 0 < 4.4.2-14.4.2-1
linuxlinux_kernel>= 0 < 4.4.2-14.4.2-1
linuxlinux_kernel>= 0 < 4.4.2-14.4.2-1
linuxlinux_kernel>= 0 < 4.4.2-14.4.2-1
linuxlinux_kernel>= 0 < 3.13.0-83.1273.13.0-83.127
suselinux_enterprise_debuginfo
suselinux_enterprise_desktop
suselinux_enterprise_module_for_public_cloud
suselinux_enterprise_real_time_extension
suselinux_enterprise_real_time_extension
suselinux_enterprise_server
suselinux_enterprise_server
suselinux_enterprise_software_development_kit
suselinux_enterprise_software_development_kit
suselinux_enterprise_workstation_extension

CVSS provenance

nvdv3.14.6MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv6.2MEDIUM