CVE-2016-3137: Canonical Ubuntu Linux
Medium severity, CVSS 4.6. EPSS: 0.5% chance of exploitation in the next 30 days.
drivers/usb/serial/cypress_m8.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a USB device without both an interrupt-in and an interrupt-out endpoint descriptor, related to the cypress_generic_port_probe and cypress_open functions.
Affected products
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only
- Linux Linux Kernel: up to and including 4.5.0
- Novell Suse Linux Enterprise Debuginfo: version 11.0 only
- Novell Suse Linux Enterprise Desktop: version 12.0 only
- Novell Suse Linux Enterprise Live Patching: version 12.0 only
- Novell Suse Linux Enterprise Module For Public Cloud: version 12.0 only
- Novell Suse Linux Enterprise Real Time Extension: version 11.0 only; version 12.0 only
- Novell Suse Linux Enterprise Server: version 11.0 only; version 12.0 only
- Novell Suse Linux Enterprise Software Development Kit: version 11.0 only; version 12.0 only
- Novell Suse Linux Enterprise Workstation Extension: version 12.0 only
Published 2016-05-02. Last modified 2026-06-17.