FlawAtlas
Search the atlas
CVE-2016-20022 High

CVE-2016-20022

In the Linux kernel before 4.8, usb_parse_endpoint in drivers/usb/core/config.c does not validate the wMaxPacketSize field of an endpoint descriptor. NOTE: This vulnerability only affects products that are no longer supported by the supplier.

Exploit probability 0.2%
Published June 27, 2024
Required by Not available
Last source change April 11, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

462 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2016-20022

In the Linux kernel before 4.8, usb_parse_endpoint in drivers/usb/core/config.c does not validate the wMaxPacketSize field of an endpoint descriptor. NOTE: This vulnerability only affects products that are no longer supported by the supplier.

View original source

05 / REFERENCES

Further evidence