Denial of Service Vulnerability in USB Drivers for Linux Kernel from Vendor Linux
CVE-2016-3137

4.6MEDIUM

Summary

A denial of service vulnerability exists in the Linux kernel USB driver for cypress_m8, allowing attackers with physical access to exploit specific USB devices. The flaw occurs due to the handling of USB devices that lack both an interrupt-in and an interrupt-out endpoint descriptor. Successful exploitation can lead to a NULL pointer dereference, resulting in a system crash, thereby compromising system availability. This affects Linux kernel versions prior to 4.5.1, emphasizing the need for users to update their systems to mitigate potential risks.

References

CVSS V3.1

Score:
4.6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.