4.9

CVE-2016-2782

Exploit
The treo_attach function in drivers/usb/serial/visor.c in the Linux kernel before 4.5 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by inserting a USB device that lacks a (1) bulk-in or (2) interrupt-in endpoint.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version < 4.5.0
Linux ≫ Linux Kernel Version 4.5.0 Update rc1
Suse ≫ Linux Enterprise Debuginfo Version 11 Update sp2
Suse ≫ Linux Enterprise Debuginfo Version 11 Update sp4
Suse ≫ Linux Enterprise Desktop Version 12 Update -
Suse ≫ Linux Enterprise Desktop Version 12 Update sp1
Suse ≫ Linux Enterprise Real Time Extension Version 11 Update sp4
Suse ≫ Linux Enterprise Real Time Extension Version 12 Update sp1
Suse ≫ Linux Enterprise Server Version 11 Update sp2 SwEdition ltss
Suse ≫ Linux Enterprise Server Version 11 Update sp4
Suse ≫ Linux Enterprise Server Version 12 Update -
Suse ≫ Linux Enterprise Server Version 12 Update sp1
Suse ≫ Linux Enterprise Workstation Extension Version 12 Update sp1
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.65% 0.734
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.6 0.9 3.6
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NIST 4.9 3.9 6.9
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE-476 NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.

http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00038.html
Third Party Advisory
Mailing List
http://www.ubuntu.com/usn/USN-2967-1
Third Party Advisory
http://www.ubuntu.com/usn/USN-2967-2
Third Party Advisory
http://www.ubuntu.com/usn/USN-2929-1
Third Party Advisory
http://www.ubuntu.com/usn/USN-2929-2
Third Party Advisory
http://www.ubuntu.com/usn/USN-2932-1
Third Party Advisory
http://www.ubuntu.com/usn/USN-2948-1
Third Party Advisory
http://www.ubuntu.com/usn/USN-2948-2
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00052.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00059.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2016-07/msg00005.html
Third Party Advisory
Mailing List
http://www.ubuntu.com/usn/USN-2930-1
Third Party Advisory
http://www.ubuntu.com/usn/USN-2930-2
Third Party Advisory
http://www.ubuntu.com/usn/USN-2930-3
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00019.html
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00054.html
Third Party Advisory
Mailing List
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=cac9b50b0d75a1d50d6c056ff65c005f3224c8e0
Patch
Vendor Advisory
Issue Tracking
http://www.openwall.com/lists/oss-security/2016/02/28/9
Third Party Advisory
Mailing List
https://bugzilla.redhat.com/show_bug.cgi?id=1312670
Third Party Advisory
Exploit
Issue Tracking
https://github.com/torvalds/linux/commit/cac9b50b0d75a1d50d6c056ff65c005f3224c8e0
Patch
Third Party Advisory
Issue Tracking
https://www.exploit-db.com/exploits/39539/
Third Party Advisory
VDB Entry