peter bassill · operator
$ cve CVE-2016-2782 JSON

CVE-2016-2782 EXPLOIT

4.6
MEDIUM · CVSS 3.1 · EPSS 1.6% (pctl 76)

Patch early

A public exploit exists.

Description

The treo_attach function in drivers/usb/serial/visor.c in the Linux kernel before 4.5 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by inserting a USB device that lacks a (1) bulk-in or (2) interrupt-in endpoint.

Scoring

CVSS4.6 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS1.65% — more likely to be exploited than 76% of all CVEs
WeaknessCWE-476
On CISA KEVno
Public exploityes
Published2016-04-27
Last modified2026-06-17

Affected (8)

VendorProduct
linuxlinux kernel
suselinux enterprise debuginfo
suselinux enterprise desktop
suselinux enterprise module for public cloud
suselinux enterprise real time extension
suselinux enterprise server
suselinux enterprise software development kit
suselinux enterprise workstation extension

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD