CVE-2016-3136: Null Pointer Dereference
A flaw was found in in the Linux kernel's USB device management code which could cause a crash when a device which required mctu232 driver. The kernel would panic caused by a null pointer dereference.
Product bug:
https://bugzilla.redhat.com/showbug.cgi?id=1283370
Other sources
The mctu232msrtostate function in drivers/usb/serial/mctu232.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted USB device without two interrupt-in endpoint descriptors.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-3136?
CVE-2016-3136 is classified as a medium severity vulnerability due to its potential to cause kernel crashes.
How do I fix CVE-2016-3136?
To fix CVE-2016-3136, upgrade your Linux kernel to version 4.5.1 or later.
Which systems are affected by CVE-2016-3136?
CVE-2016-3136 affects various versions of the Linux Kernel up to 4.5.0, as well as specific versions of SUSE Linux and Ubuntu.
What causes the vulnerability CVE-2016-3136?
The vulnerability is caused by a null pointer dereference in the USB device management code within the Linux kernel.
Can CVE-2016-3136 be exploited remotely?
While CVE-2016-3136 is primarily related to USB device interactions, it's essential to avoid connecting vulnerable devices to mitigate potential risks.