Denial of Service Vulnerability in Linux Kernel Affecting Wacom Drivers
CVE-2016-3139

4.6MEDIUM

What is CVE-2016-3139?

The wacom_probe function in the Linux kernel prior to version 3.17 is susceptible to a denial of service condition. Attackers with physical access can exploit this vulnerability by providing a crafted endpoints value in a USB device descriptor, resulting in a NULL pointer dereference and subsequent system crash. This threat underscores the importance of securing system access and ensuring that USB inputs are validated to prevent exploitation.

References

CVSS V3.1

Score:
4.6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.