CVE-2016-20022
High severity, CVSS 8.4. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel before 4.8, usb_parse_endpoint in drivers/usb/core/config.c does not validate the wMaxPacketSize field of an endpoint descriptor. NOTE: This vulnerability only affects products that are no longer supported by the supplier.
Published 2024-06-27. Last modified 2026-06-17.