UBUNTU-CVE-2015-7566
The clie_5_attach function in drivers/usb/serial/visor.c in the Linux kernel through 4.4.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by inserting a USB device that lacks a bulk-out endpoint.
02 / AFFECTED SOFTWARE
Affected packages
86 explicit affected versions
38 explicit affected versions
22 explicit affected versions
9 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
The clie_5_attach function in drivers/usb/serial/visor.c in the Linux kernel through 4.4.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by inserting a USB device that lacks a bulk-out endpoint.
05 / REFERENCES
Further evidence
- http://marc.info/?l=linux-usb&m=145260786729359&w=2
- https://bugzilla.redhat.com/show_bug.cgi?id=1283371
- https://ubuntu.com/security/CVE-2015-7566
- https://ubuntu.com/security/notices/USN-2929-1
- https://ubuntu.com/security/notices/USN-2929-2
- https://ubuntu.com/security/notices/USN-2930-1
- https://ubuntu.com/security/notices/USN-2930-2
- https://ubuntu.com/security/notices/USN-2930-3
- https://ubuntu.com/security/notices/USN-2932-1
- https://ubuntu.com/security/notices/USN-2948-1
- https://ubuntu.com/security/notices/USN-2967-1
- https://ubuntu.com/security/notices/USN-2967-2
- https://www.cve.org/CVERecord?id=CVE-2015-7566