Lucene search

K
cveRedhatCVE-2015-7566
HistoryFeb 08, 2016 - 3:59 a.m.

CVE-2015-7566

2016-02-0803:59:03
redhat
web.nvd.nist.gov
112
cve-2015-7566
linux kernel
usb device
null pointer dereference
denial of service
nvd

CVSS2

4.9

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:N/I:N/A:C

CVSS3

4.6

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

6

Confidence

High

EPSS

0.004

Percentile

72.1%

The clie_5_attach function in drivers/usb/serial/visor.c in the Linux kernel through 4.4.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by inserting a USB device that lacks a bulk-out endpoint.

Affected configurations

Nvd
Node
novellsuse_linux_enterprise_software_development_kitMatch11sp4
OR
novellsuse_linux_enterprise_debuginfoMatch11sp4
OR
novellsuse_linux_enterprise_real_time_extensionMatch11sp4
OR
novellsuse_linux_enterprise_real_time_extensionMatch12sp1
OR
novellsuse_linux_enterprise_serverMatch11extra
OR
novellsuse_linux_enterprise_serverMatch11sp4
Node
linuxlinux_kernelRange4.4.1
VendorProductVersionCPE
novellsuse_linux_enterprise_software_development_kit11cpe:2.3:a:novell:suse_linux_enterprise_software_development_kit:11:sp4:*:*:*:*:*:*
novellsuse_linux_enterprise_debuginfo11cpe:2.3:o:novell:suse_linux_enterprise_debuginfo:11:sp4:*:*:*:*:*:*
novellsuse_linux_enterprise_real_time_extension11cpe:2.3:o:novell:suse_linux_enterprise_real_time_extension:11:sp4:*:*:*:*:*:*
novellsuse_linux_enterprise_real_time_extension12cpe:2.3:o:novell:suse_linux_enterprise_real_time_extension:12:sp1:*:*:*:*:*:*
novellsuse_linux_enterprise_server11cpe:2.3:o:novell:suse_linux_enterprise_server:11:extra:*:*:*:*:*:*
novellsuse_linux_enterprise_server11cpe:2.3:o:novell:suse_linux_enterprise_server:11:sp4:*:*:*:*:*:*
linuxlinux_kernel*cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

References

CVSS2

4.9

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:N/I:N/A:C

CVSS3

4.6

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

6

Confidence

High

EPSS

0.004

Percentile

72.1%