CVE-2016-3139
published 2016-04-27CVE-2016-3139: The wacom_probe function in drivers/input/tablet/wacom_sys.c in the Linux kernel before 3.17 allows physically proximate attackers to cause a denial of service…
PriorityP421medium4.6CVSS 3.0
AVPACLPRNUINSUCNINAH
EXPLOIT
EPSS
1.79%
75.9th percentile
The wacom_probe function in drivers/input/tablet/wacom_sys.c in the Linux kernel before 3.17 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB device descriptor.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.0.2-1 (bookworm) | linux 4.0.2-1 (bookworm) |
| linux | linux_kernel | <= 3.16.7 | — |
| linux | linux_kernel | >= 0 < 4.0.2-1 | 4.0.2-1 |
| linux | linux_kernel | >= 0 < 4.0.2-1 | 4.0.2-1 |
| linux | linux_kernel | >= 0 < 4.0.2-1 | 4.0.2-1 |
| linux | linux_kernel | >= 0 < 4.0.2-1 | 4.0.2-1 |
| novell | suse_linux_enterprise_debuginfo | — | — |
| novell | suse_linux_enterprise_desktop | — | — |
| novell | suse_linux_enterprise_live_patching | — | — |
| novell | suse_linux_enterprise_module_for_public_cloud | — | — |
| novell | suse_linux_enterprise_real_time_extension | — | — |
| novell | suse_linux_enterprise_real_time_extension | — | — |
| novell | suse_linux_enterprise_server | — | — |
| novell | suse_linux_enterprise_server | — | — |
| novell | suse_linux_enterprise_software_development_kit | — | — |
| novell | suse_linux_enterprise_software_development_kit | — | — |
| novell | suse_linux_enterprise_workstation_extension | — | — |
CVSS provenance
nvdv3.04.6MEDIUMCVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv4.6MEDIUM
vendor_debian4.6LOW
vendor_redhat4.6MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q835-79mw-g5c8: The wacom_probe function in drivers/input/tablet/wacom_sys
ghsa_unreviewed·2022-05-17
CVE-2016-3139 [MEDIUM] GHSA-q835-79mw-g5c8: The wacom_probe function in drivers/input/tablet/wacom_sys
The wacom_probe function in drivers/input/tablet/wacom_sys.c in the Linux kernel before 3.17 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB device descriptor.
OSV
CVE-2016-3139: The wacom_probe function in drivers/input/tablet/wacom_sys
osv·2016-04-27·CVSS 4.6
CVE-2016-3139 [MEDIUM] CVE-2016-3139: The wacom_probe function in drivers/input/tablet/wacom_sys
The wacom_probe function in drivers/input/tablet/wacom_sys.c in the Linux kernel before 3.17 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB device descriptor.
Red Hat
kernel: Crash on invalid USB device descriptors (wacom driver)
vendor_redhat·2016-03-09·CVSS 4.6
CVE-2016-3139 [MEDIUM] CWE-476 kernel: Crash on invalid USB device descriptors (wacom driver)
kernel: Crash on invalid USB device descriptors (wacom driver)
The wacom_probe function in drivers/input/tablet/wacom_sys.c in the Linux kernel before 3.17 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB device descriptor.
Statement: This issue affects the Linux kernel packages as shipped with Red Hat Enterprise Linux 5, 6, 7 and MRG-2. This has been rated as having Low security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.
Package: kernel (Red Hat Enterprise Linux 5) - Will not fix
Package: kernel (Red Hat Enterprise Linux 6)
Debian
CVE-2016-3139: linux - The wacom_probe function in drivers/input/tablet/wacom_sys.c in the Linux kernel...
vendor_debian·2016·CVSS 4.6
CVE-2016-3139 [MEDIUM] CVE-2016-3139: linux - The wacom_probe function in drivers/input/tablet/wacom_sys.c in the Linux kernel...
The wacom_probe function in drivers/input/tablet/wacom_sys.c in the Linux kernel before 3.17 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB device descriptor.
Scope: local
bookworm: resolved (fixed in 4.0.2-1)
bullseye: resolved (fixed in 4.0.2-1)
forky: resolved (fixed in 4.0.2-1)
sid: resolved (fixed in 4.0.2-1)
trixie: resolved (fixed in 4.0.2-1)
No detection rules found.
Bugzilla
CVE-2016-3138 CVE-2016-3139 CVE-2016-3140 CVE-2016-3137 CVE-2016-3136 CVE-2016-2184 CVE-2016-2185 CVE-2016-2186 CVE-2016-2187 CVE-2016-2188 kernel: various crashes on invalid usb device descriptors [f
bugzilla·2016-03-11·CVSS 4.6
CVE-2016-3138 [MEDIUM] CVE-2016-3138 CVE-2016-3139 CVE-2016-3140 CVE-2016-3137 CVE-2016-3136 CVE-2016-2184 CVE-2016-2185 CVE-2016-2186 CVE-2016-2187 CVE-2016-2188 kernel: various crashes on invalid usb device descriptors [f
CVE-2016-3138 CVE-2016-3139 CVE-2016-3140 CVE-2016-3137 CVE-2016-3136 CVE-2016-2184 CVE-2016-2185 CVE-2016-2186 CVE-2016-2187 CVE-2016-2188 kernel: various crashes on invalid usb device descriptors [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention
Bugzilla
CVE-2016-3139 kernel: Crash on invalid USB device descriptors (wacom driver)
bugzilla·2016-03-11·CVSS 4.6
CVE-2016-3139 [MEDIUM] CVE-2016-3139 kernel: Crash on invalid USB device descriptors (wacom driver)
CVE-2016-3139 kernel: Crash on invalid USB device descriptors (wacom driver)
Kernel crash occurs when presented a buggy USB device which requires wacom driver, causing null pointer dereference.
Product bugs:
https://bugzilla.redhat.com/show_bug.cgi?id=1283375
https://bugzilla.redhat.com/show_bug.cgi?id=1283377
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1317010]
---
Public via:
http://seclists.org/bugtraq/2016/Mar/60
CVE request and assignment:
http://seclists.org/oss-sec/2016/q1/606
http://seclists.org/oss-sec/2016/q1/623
Upstream commit: the upstream driver was rebased and does not have this bug, so this bug is rhel7-only and there is no upstream commit.
---
Acknowledgements:
Name: Ralf Spenneberg (OpenSource Security)
---
Statement
Bugzilla
CVE-2016-3139 Local RedHat Enterprise Linux DoS – RHEL 7.1 Kernel crashes on invalid USB device descriptors (wacom driver) [local-DoS] Bug2
bugzilla·2015-11-18·CVSS 4.6
CVE-2016-3139 [MEDIUM] CVE-2016-3139 Local RedHat Enterprise Linux DoS – RHEL 7.1 Kernel crashes on invalid USB device descriptors (wacom driver) [local-DoS] Bug2
CVE-2016-3139 Local RedHat Enterprise Linux DoS – RHEL 7.1 Kernel crashes on invalid USB device descriptors (wacom driver) [local-DoS] Bug2
Description of problem:
Local RedHat Enterprise Linux DoS – RHEL 7.1 Kernel crashes on invalid
USB device descriptors (wacom driver) [local-DoS]
Bug2
Version-Release number of selected component (if applicable):
Kernel-Version: 3.10.0-229.20.1.el7.x86_64
How reproducible:
always
OpenSource Security Ralf Spenneberg
Am Bahnhof 3-5
48565 Steinfurt
[email protected]
Date: November 12th, 2015
Authors: Sergej Schumilo, Hendrik Schwartke, Ralf Spenneberg
CVE: not yet assigned
CVSS: 4.9 (AV:L/AC:L/Au:N/C:N/I:N/A:C)
Title: Local RedHat Enterprise Linux DoS – RHEL 7.1 Kernel crashes on invalid
USB device descriptors (wacom driver) [local-DoS]
Severity: Critica
Bugzilla
CVE-2016-3139 Local RedHat Enterprise Linux DoS – RHEL 7.1 Kernel crashes on invalid USB device descriptors (wacom driver) [local-DoS]
bugzilla·2015-11-18·CVSS 4.6
CVE-2016-3139 [MEDIUM] CVE-2016-3139 Local RedHat Enterprise Linux DoS – RHEL 7.1 Kernel crashes on invalid USB device descriptors (wacom driver) [local-DoS]
CVE-2016-3139 Local RedHat Enterprise Linux DoS – RHEL 7.1 Kernel crashes on invalid USB device descriptors (wacom driver) [local-DoS]
Description of problem:
Local RedHat Enterprise Linux DoS – RHEL 7.1 Kernel crashes on invalid
USB device descriptors (wacom driver) [local-DoS]
Version-Release number of selected component (if applicable):
Kernel-Version: 3.10.0-229.20.1.el7.x86_64
How reproducible:
always
OpenSource Security Ralf Spenneberg
Am Bahnhof 3-5
48565 Steinfurt
[email protected]
Date: November 12th, 2015
Authors: Sergej Schumilo, Hendrik Schwartke, Ralf Spenneberg
CVE: not yet assigned
CVSS: 4.9 (AV:L/AC:L/Au:N/C:N/I:N/A:C)
Title: Local RedHat Enterprise Linux DoS – RHEL 7.1 Kernel crashes on invalid
USB device descriptors (wacom driver) [local-DoS]
Severity: Critical. The Ker
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=471d17148c8b4174ac5f5283a73316d12c4379bchttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00019.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00052.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00054.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00059.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-07/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00038.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1283375https://bugzilla.redhat.com/show_bug.cgi?id=1283377https://bugzilla.redhat.com/show_bug.cgi?id=1316993https://github.com/torvalds/linux/commit/471d17148c8b4174ac5f5283a73316d12c4379bchttps://security-tracker.debian.org/tracker/CVE-2016-3139https://www.exploit-db.com/exploits/39538/http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=471d17148c8b4174ac5f5283a73316d12c4379bchttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00019.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00052.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00054.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00059.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-07/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00038.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1283375https://bugzilla.redhat.com/show_bug.cgi?id=1283377https://bugzilla.redhat.com/show_bug.cgi?id=1316993https://github.com/torvalds/linux/commit/471d17148c8b4174ac5f5283a73316d12c4379bchttps://security-tracker.debian.org/tracker/CVE-2016-3139https://www.exploit-db.com/exploits/39538/
2016-04-27
Published