First published: Fri Mar 11 2016(Updated: )
A flaw was found in in the Linux kernel's USB device management code which could cause a crash when a device which required cypress_m8 driver. The kernel would panic causing null pointer dereference. Product bug: <a class="bz_bug_link bz_status_CLOSED bz_closed bz_public " title="CLOSED WONTFIX - CVE-2016-3137 Local RedHat Enterprise Linux DoS – RHEL 7.1 Kernel crashes on invalid USB device descriptors (cypress_m8 driver) [local-DoS]" href="show_bug.cgi?id=1283368">https://bugzilla.redhat.com/show_bug.cgi?id=1283368</a>
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Enterprise Linux | ||
Red Hat Kernel-devel |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-1316996 is considered significant due to the potential for kernel panic and system crash.
To fix REDHAT-BUG-1316996, update the system kernel to the latest version provided by Red Hat that addresses this vulnerability.
REDHAT-BUG-1316996 affects Red Hat Enterprise Linux and the Linux Kernel that utilize the cypress_m8 driver.
The issue in REDHAT-BUG-1316996 is caused by a null pointer dereference in the USB device management code of the Linux kernel.
Currently, there are no widely suggested workarounds for REDHAT-BUG-1316996 except for applying the kernel update when available.