Denial of Service Vulnerability in Linux Kernel Affecting Various Distributions
CVE-2016-2188
4.6MEDIUM
Key Information:
- Vendor
Novell
- Status
- Vendor
- CVE Published:
- 2 May 2016
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2016-2188?
The iowarrior_probe function in the Linux kernel prior to version 4.5.1 is susceptible to a denial of service attack. This vulnerability allows an attacker with physical access to cause a system crash through a NULL pointer dereference resulting from a crafted endpoints value in a USB device descriptor. Such exploits could lead to significant disruptions in services for affected systems, especially in environments where physical access to devices is less controlled.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.