First published: Fri Mar 11 2016(Updated: )
Kernel crash occurs when presented a buggy USB device which requires wacom driver, causing null pointer dereference. Product bugs: <a class="bz_bug_link bz_status_CLOSED bz_closed bz_public " title="CLOSED WONTFIX - CVE-2016-3139 Local RedHat Enterprise Linux DoS – RHEL 7.1 Kernel crashes on invalid USB device descriptors (wacom driver) [local-DoS]" href="show_bug.cgi?id=1283375">https://bugzilla.redhat.com/show_bug.cgi?id=1283375</a> <a class="bz_bug_link bz_status_CLOSED bz_closed bz_public " title="CLOSED WONTFIX - CVE-2016-3139 Local RedHat Enterprise Linux DoS – RHEL 7.1 Kernel crashes on invalid USB device descriptors (wacom driver) [local-DoS] Bug2" href="show_bug.cgi?id=1283377">https://bugzilla.redhat.com/show_bug.cgi?id=1283377</a>
Credit: meissner@suse.de meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
debian/linux | 5.10.218-1 5.10.221-1 6.1.94-1 6.1.99-1 6.9.12-1 6.10.3-1 | |
SUSE Linux Enterprise Software Development Kit | =11.0-sp4 | |
SUSE Linux Enterprise Software Development Kit | =12.0 | |
SUSE Linux Enterprise Debuginfo | =11.0-sp4 | |
SUSE Linux Enterprise Desktop | =12.0 | |
SUSE Linux Enterprise Live Patching | =12.0 | |
SUSE Linux Enterprise Module for Public Cloud | =12.0 | |
SUSE Linux Enterprise Real Time Extension | =11.0-sp4 | |
SUSE Linux Enterprise Real Time Extension | =12.0-sp1 | |
SUSE Linux Enterprise Server | =11.0-extra | |
SUSE Linux Enterprise Server | =11.0-sp4 | |
SUSE Linux Enterprise Server | =12.0 | |
SUSE Linux Enterprise Workstation Extension | =12.0 | |
Linux Kernel | <=3.16.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-3139 is classified with high severity due to its potential to cause a kernel crash.
To resolve CVE-2016-3139, upgrade to the patched versions specified in the affected software section.
CVE-2016-3139 affects various versions of the Linux kernel, specifically those earlier than 5.10.218-1 and 6.1.99-1.
CVE-2016-3139 results from a null pointer dereference triggered by a buggy USB device that requires the wacom driver.
There are no effective workarounds for CVE-2016-3139; users are advised to apply the available updates.