CVE-2016-2782

The treo_attach function in drivers/usb/serial/visor.c in the Linux kernel before 4.5 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by inserting a USB device that lacks a (1) bulk-in or (2) interrupt-in endpoint.
References
Link Resource
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=cac9b50b0d75a1d50d6c056ff65c005f3224c8e0 Issue Tracking Patch Vendor Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00019.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00052.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00054.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00059.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-07/msg00005.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00038.html Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2016/02/28/9 Mailing List Third Party Advisory
http://www.ubuntu.com/usn/USN-2929-1 Third Party Advisory
http://www.ubuntu.com/usn/USN-2929-2 Third Party Advisory
http://www.ubuntu.com/usn/USN-2930-1 Third Party Advisory
http://www.ubuntu.com/usn/USN-2930-2 Third Party Advisory
http://www.ubuntu.com/usn/USN-2930-3 Third Party Advisory
http://www.ubuntu.com/usn/USN-2932-1 Third Party Advisory
http://www.ubuntu.com/usn/USN-2948-1 Third Party Advisory
http://www.ubuntu.com/usn/USN-2948-2 Third Party Advisory
http://www.ubuntu.com/usn/USN-2967-1 Third Party Advisory
http://www.ubuntu.com/usn/USN-2967-2 Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1312670 Exploit Issue Tracking Third Party Advisory
https://github.com/torvalds/linux/commit/cac9b50b0d75a1d50d6c056ff65c005f3224c8e0 Issue Tracking Patch Third Party Advisory
https://www.exploit-db.com/exploits/39539/ Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:4.5.0:rc1:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:suse:linux_enterprise_debuginfo:11:sp2:*:*:*:*:*:*
cpe:2.3:a:suse:linux_enterprise_debuginfo:11:sp4:*:*:*:*:*:*
cpe:2.3:a:suse:linux_enterprise_module_for_public_cloud:12:*:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_desktop:12:-:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_desktop:12:sp1:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_real_time_extension:11:sp4:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_real_time_extension:12:sp1:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:11:sp2:*:*:ltss:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:11:sp4:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:12:-:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:12:sp1:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_software_development_kit:11:sp4:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_software_development_kit:12:-:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_software_development_kit:12:sp1:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_workstation_extension:12:*:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_workstation_extension:12:sp1:*:*:*:*:*:*

History

31 Jan 2022, 18:02

Type Values Removed Values Added
References (UBUNTU) http://www.ubuntu.com/usn/USN-2929-2 - (UBUNTU) http://www.ubuntu.com/usn/USN-2929-2 - Third Party Advisory
References (CONFIRM) http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=cac9b50b0d75a1d50d6c056ff65c005f3224c8e0 - Vendor Advisory (CONFIRM) http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=cac9b50b0d75a1d50d6c056ff65c005f3224c8e0 - Issue Tracking, Patch, Vendor Advisory
References (UBUNTU) http://www.ubuntu.com/usn/USN-2948-2 - (UBUNTU) http://www.ubuntu.com/usn/USN-2948-2 - Third Party Advisory
References (SUSE) http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00038.html - (SUSE) http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00038.html - Mailing List, Third Party Advisory
References (SUSE) http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00052.html - Third Party Advisory (SUSE) http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00052.html - Mailing List, Third Party Advisory
References (UBUNTU) http://www.ubuntu.com/usn/USN-2929-1 - (UBUNTU) http://www.ubuntu.com/usn/USN-2929-1 - Third Party Advisory
References (EXPLOIT-DB) https://www.exploit-db.com/exploits/39539/ - (EXPLOIT-DB) https://www.exploit-db.com/exploits/39539/ - Third Party Advisory, VDB Entry
References (SUSE) http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00054.html - Third Party Advisory (SUSE) http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00054.html - Mailing List, Third Party Advisory
References (SUSE) http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00019.html - (SUSE) http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00019.html - Third Party Advisory
References (UBUNTU) http://www.ubuntu.com/usn/USN-2930-1 - (UBUNTU) http://www.ubuntu.com/usn/USN-2930-1 - Third Party Advisory
References (UBUNTU) http://www.ubuntu.com/usn/USN-2967-2 - (UBUNTU) http://www.ubuntu.com/usn/USN-2967-2 - Third Party Advisory
References (UBUNTU) http://www.ubuntu.com/usn/USN-2948-1 - (UBUNTU) http://www.ubuntu.com/usn/USN-2948-1 - Third Party Advisory
References (MLIST) http://www.openwall.com/lists/oss-security/2016/02/28/9 - (MLIST) http://www.openwall.com/lists/oss-security/2016/02/28/9 - Mailing List, Third Party Advisory
References (SUSE) http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00059.html - Third Party Advisory (SUSE) http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00059.html - Mailing List, Third Party Advisory
References (SUSE) http://lists.opensuse.org/opensuse-security-announce/2016-07/msg00005.html - Third Party Advisory (SUSE) http://lists.opensuse.org/opensuse-security-announce/2016-07/msg00005.html - Mailing List, Third Party Advisory
References (UBUNTU) http://www.ubuntu.com/usn/USN-2967-1 - (UBUNTU) http://www.ubuntu.com/usn/USN-2967-1 - Third Party Advisory
References (UBUNTU) http://www.ubuntu.com/usn/USN-2932-1 - (UBUNTU) http://www.ubuntu.com/usn/USN-2932-1 - Third Party Advisory
References (UBUNTU) http://www.ubuntu.com/usn/USN-2930-2 - (UBUNTU) http://www.ubuntu.com/usn/USN-2930-2 - Third Party Advisory
References (CONFIRM) https://bugzilla.redhat.com/show_bug.cgi?id=1312670 - Issue Tracking (CONFIRM) https://bugzilla.redhat.com/show_bug.cgi?id=1312670 - Exploit, Issue Tracking, Third Party Advisory
References (UBUNTU) http://www.ubuntu.com/usn/USN-2930-3 - (UBUNTU) http://www.ubuntu.com/usn/USN-2930-3 - Third Party Advisory
References (CONFIRM) https://github.com/torvalds/linux/commit/cac9b50b0d75a1d50d6c056ff65c005f3224c8e0 - Vendor Advisory (CONFIRM) https://github.com/torvalds/linux/commit/cac9b50b0d75a1d50d6c056ff65c005f3224c8e0 - Issue Tracking, Patch, Third Party Advisory
CPE cpe:2.3:o:novell:suse_linux_enterprise_live_patching:12:*:*:*:*:*:*:*
cpe:2.3:o:novell:suse_linux_enterprise_real_time_extension:12:sp1:*:*:*:*:*:*
cpe:2.3:o:novell:suse_linux_enterprise_workstation_extension:12:*:*:*:*:*:*:*
cpe:2.3:o:novell:suse_linux_enterprise_server:11:sp4:*:*:*:*:*:*
cpe:2.3:o:novell:suse_linux_enterprise_debuginfo:11:sp4:*:*:*:*:*:*
cpe:2.3:o:novell:suse_linux_enterprise_real_time_extension:11:sp4:*:*:*:*:*:*
cpe:2.3:o:novell:suse_linux_enterprise_server:12.0:*:*:*:*:*:*:*
cpe:2.3:o:novell:suse_linux_enterprise_module_for_public_cloud:12:*:*:*:*:*:*:*
cpe:2.3:o:novell:suse_linux_enterprise_server:11:extra:*:*:*:*:*:*
cpe:2.3:o:novell:suse_linux_enterprise_software_development_kit:12:*:*:*:*:*:*:*
cpe:2.3:o:novell:suse_linux_enterprise_desktop:12.0:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:rc7:*:*:*:*:*:*
cpe:2.3:o:novell:suse_linux_enterprise_software_development_kit:11.0:sp4:*:*:*:*:*:*
cpe:2.3:a:suse:linux_enterprise_debuginfo:11:sp2:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_real_time_extension:11:sp4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:4.5.0:rc1:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_real_time_extension:12:sp1:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:12:sp1:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_workstation_extension:12:*:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_software_development_kit:11:sp4:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_software_development_kit:12:-:*:*:*:*:*:*
cpe:2.3:a:suse:linux_enterprise_debuginfo:11:sp4:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:11:sp4:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_desktop:12:-:*:*:*:*:*:*
cpe:2.3:a:suse:linux_enterprise_module_for_public_cloud:12:*:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:12:-:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:11:sp2:*:*:ltss:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_workstation_extension:12:sp1:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_desktop:12:sp1:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_software_development_kit:12:sp1:*:*:*:*:*:*
CWE NVD-CWE-Other CWE-476

Information

Published : 2016-04-27 17:59

Updated : 2024-02-04 18:53


NVD link : CVE-2016-2782

Mitre link : CVE-2016-2782

CVE.ORG link : CVE-2016-2782


JSON object : View

Products Affected

suse

  • linux_enterprise_module_for_public_cloud
  • linux_enterprise_debuginfo
  • linux_enterprise_real_time_extension
  • linux_enterprise_desktop
  • linux_enterprise_server
  • linux_enterprise_workstation_extension
  • linux_enterprise_software_development_kit

linux

  • linux_kernel
CWE
CWE-476

NULL Pointer Dereference