CVE-2016-2782: Linux Kernel

Medium severity, CVSS 4.6. EPSS: 1.6% chance of exploitation in the next 30 days.

The treo_attach function in drivers/usb/serial/visor.c in the Linux kernel before 4.5 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by inserting a USB device that lacks a (1) bulk-in or (2) interrupt-in endpoint.

Affected products

  • Linux Linux Kernel: before 4.5.0 (fixed in 4.5.0); version 4.5.0 only
  • Suse Linux Enterprise Debuginfo: version 11 only
  • Suse Linux Enterprise Desktop: version 12 only
  • Suse Linux Enterprise Module For Public Cloud: version 12 only
  • Suse Linux Enterprise Real Time Extension: version 11 only; version 12 only
  • Suse Linux Enterprise Server: version 11 only; version 12 only
  • Suse Linux Enterprise Software Development Kit: version 11 only; version 12 only
  • Suse Linux Enterprise Workstation Extension: version 12 only

Published 2016-04-27. Last modified 2026-06-17.