CVE-2016-3689

Severity
4.6MEDIUM
EPSS
0.1%
top 74.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 2
Latest updateMay 17

Description

The ims_pcu_parse_cdc_data function in drivers/input/misc/ims-pcu.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (system crash) via a USB device without both a master and a slave interface.

CVSS vector

CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 0.9 | Impact: 3.6

Affected Packages9 packages

Also affects: Ubuntu Linux 14.04

🔴Vulnerability Details

3
GHSA
GHSA-r6x3-3gvp-pgpm: The ims_pcu_parse_cdc_data function in drivers/input/misc/ims-pcu2022-05-17
OSV
CVE-2016-3689: The ims_pcu_parse_cdc_data function in drivers/input/misc/ims-pcu2016-05-02
CVEList
CVE-2016-3689: The ims_pcu_parse_cdc_data function in drivers/input/misc/ims-pcu2016-05-02

📋Vendor Advisories

13
Ubuntu
Linux kernel (Utopic HWE) vulnerabilities2016-06-10
Ubuntu
Linux kernel (Wily HWE) vulnerabilities2016-05-09
Ubuntu
Linux kernel vulnerabilities2016-05-09
Ubuntu
Linux kernel (Vivid HWE) vulnerabilities2016-05-09
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities2016-05-09

💬Community

2
Bugzilla
CVE-2016-3689 kernel: denial of service via malicious device using ims-pcu driver [fedora-all]2016-03-22
Bugzilla
CVE-2016-3689 kernel: denial of service via malicious device using ims-pcu driver2016-03-22