CVE-2016-2184: Null Pointer Dereference
A flaw was found in in the Linux kernel's USB device management code which could cause a crash when a device which required sndusbaudio driver. The kernel would panic causing null pointer dereference attempting to access non existent endpoints.
Product bugs:
https://bugzilla.redhat.com/showbug.cgi?id=1283355 https://bugzilla.redhat.com/showbug.cgi?id=1283358
Other sources
The createfixedstreamquirk function in sound/usb/quirks.c in the snd-usb-audio driver in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference or double free, and system crash) via a crafted endpoints value in a USB device descriptor.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2184?
CVE-2016-2184 has a medium severity rating due to its potential to cause a kernel panic.
How do I fix CVE-2016-2184?
To fix CVE-2016-2184, users should upgrade to a patched version of the Linux kernel or the affected operating system.
Which products are affected by CVE-2016-2184?
CVE-2016-2184 affects various versions of the Linux kernel and specific distributions like Ubuntu and SUSE Linux.
What attack vectors are associated with CVE-2016-2184?
CVE-2016-2184 can be triggered by connecting USB devices that require the snd_usb_audio driver.
Is there a known exploit for CVE-2016-2184?
As of now, there are no publicly available exploits specifically targeting CVE-2016-2184.