CVE-2016-3139: Null Pointer Dereference
Kernel crash occurs when presented a buggy USB device which requires wacom driver, causing null pointer dereference.
Product bugs:
https://bugzilla.redhat.com/showbug.cgi?id=1283375 https://bugzilla.redhat.com/showbug.cgi?id=1283377
Other sources
The wacomprobe function in drivers/input/tablet/wacomsys.c in the Linux kernel before 3.17 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB device descriptor.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-3139?
CVE-2016-3139 is classified with high severity due to its potential to cause a kernel crash.
How do I fix CVE-2016-3139?
To resolve CVE-2016-3139, upgrade to the patched versions specified in the affected software section.
Which software versions are affected by CVE-2016-3139?
CVE-2016-3139 affects various versions of the Linux kernel, specifically those earlier than 5.10.218-1 and 6.1.99-1.
What causes the vulnerability in CVE-2016-3139?
CVE-2016-3139 results from a null pointer dereference triggered by a buggy USB device that requires the wacom driver.
Is there a workaround for CVE-2016-3139?
There are no effective workarounds for CVE-2016-3139; users are advised to apply the available updates.