CVE-2016-3689: Medium severity suse linux enterprise software development kit vulnerability
A vulnerability was found in the Linux kernel. A device pretending to be a device driven by the ims-pcu driver but leaving out either of the two interfaces present on the genuine device will oops the driver.
Reference with proposed fix:
https://bugzilla.novell.com/showbug.cgi?id=971628
Linux-input maintainer tree patch:
https://kernel.googlesource.com/pub/scm/linux/kernel/git/dtor/input/+/a0ad220c96692eda76b2e3fd7279f3dcd1d8a8ff
An upstream patch:
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=a0ad220c96692eda76b2e3fd7279f3dcd1d8a8ff
CVE-ID request: http://seclists.org/oss-sec/2016/q1/715
CVE-ID assignment: http://seclists.org/oss-sec/2016/q1/717
Other sources
The imspcuparsecdcdata function in drivers/input/misc/ims-pcu.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (system crash) via a USB device without both a master and a slave interface.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-3689?
CVE-2016-3689 is classified as a medium severity vulnerability that can cause a system crash when exploited.
How do I fix CVE-2016-3689?
To fix CVE-2016-3689, upgrade to the patched versions of the Linux kernel, specifically to versions 5.10.223-1, 5.10.226-1, 6.1.123-1, 6.1.119-1, 6.12.10-1, or 6.12.11-1.
Which versions of the Linux kernel are affected by CVE-2016-3689?
CVE-2016-3689 affects Linux kernels up to version 4.5.0.
What systems are impacted by CVE-2016-3689?
CVE-2016-3689 primarily impacts SUSE Linux Enterprise products and Ubuntu Linux 14.04.
What are the potential consequences of not addressing CVE-2016-3689?
Failing to address CVE-2016-3689 may result in system crashes, potentially leading to downtime and loss of data.