PT-2016-5381 · Linux+3 · Linux Kernel+3

Ralf Spenneberg

·

Published

2016-04-13

·

Updated

2023-09-12

·

CVE-2016-3138

CVSS v2.0

4.9

Medium

VectorAV:L/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 4.5.1
Description The issue allows physically proximate attackers to cause a denial of service, resulting in a NULL pointer dereference and system crash, via a USB device without both a control and a data endpoint descriptor. This is due to a problem in the acm probe function in drivers/usb/class/cdc-acm.c.
Recommendations For Linux kernel versions prior to 4.5.1, update to version 4.5.1 or later to resolve the issue.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALT-PU-2016-1331
ALT-PU-2017-1330
CVE-2016-3138
DLA-516-1
DSA-3607-1
OPENSUSE-SU-2016_1382-1
OPENSUSE-SU-2016_2144-1
SUSE-SU-2016:1203-1
SUSE-SU-2016:1672-1
SUSE-SU-2016:1690-1
SUSE-SU-2016:1696-1
SUSE-SU-2016:1707-1
SUSE-SU-2016:1764-1
SUSE-SU-2016:2074-1
USN-2965-1
USN-2965-2
USN-2965-3
USN-2965-4
USN-2968-1
USN-2968-2
USN-2969-1
USN-2970-1
USN-2971-1
USN-2971-2
USN-2971-3
USN-2996-1
USN-2997-1

Affected Products

Alt Linux
Linux Kernel
Suse
Ubuntu