CVE-2016-3139: Linux Kernel

Medium severity, CVSS 4.6. EPSS: 1.8% chance of exploitation in the next 30 days.

The wacom_probe function in drivers/input/tablet/wacom_sys.c in the Linux kernel before 3.17 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB device descriptor.

Affected products

  • Linux Linux Kernel: up to and including 3.16.7
  • Novell Suse Linux Enterprise Debuginfo: version 11.0 only
  • Novell Suse Linux Enterprise Desktop: version 12.0 only
  • Novell Suse Linux Enterprise Live Patching: version 12.0 only
  • Novell Suse Linux Enterprise Module For Public Cloud: version 12.0 only
  • Novell Suse Linux Enterprise Real Time Extension: version 11.0 only; version 12.0 only
  • Novell Suse Linux Enterprise Server: version 11.0 only; version 12.0 only
  • Novell Suse Linux Enterprise Software Development Kit: version 11.0 only; version 12.0 only
  • Novell Suse Linux Enterprise Workstation Extension: version 12.0 only

Published 2016-04-27. Last modified 2026-06-17.