CVE-2016-2782: Linux Kernel
Medium severity, CVSS 4.6. EPSS: 1.6% chance of exploitation in the next 30 days.
The treo_attach function in drivers/usb/serial/visor.c in the Linux kernel before 4.5 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by inserting a USB device that lacks a (1) bulk-in or (2) interrupt-in endpoint.
Affected products
- Linux Linux Kernel: before 4.5.0 (fixed in 4.5.0); version 4.5.0 only
- Suse Linux Enterprise Debuginfo: version 11 only
- Suse Linux Enterprise Desktop: version 12 only
- Suse Linux Enterprise Module For Public Cloud: version 12 only
- Suse Linux Enterprise Real Time Extension: version 11 only; version 12 only
- Suse Linux Enterprise Server: version 11 only; version 12 only
- Suse Linux Enterprise Software Development Kit: version 11 only; version 12 only
- Suse Linux Enterprise Workstation Extension: version 12 only
Published 2016-04-27. Last modified 2026-06-17.