CVE-2015-7566
Linux Kernel 3.10.0 (CentOS / RHEL 7.1) - visor clie_5_attach Nullpointer Dereference
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The clie_5_attach function in drivers/usb/serial/visor.c in the Linux kernel through 4.4.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by inserting a USB device that lacks a bulk-out endpoint.
La función clie_5_attach en drivers/usb/serial/visor.c en el kernel de Linux hasta la versión 4.4.1 permite a atacantes físicamente próximos provocar una denegación de servicio (referencia a puntero NULL y caída del sistema) o posiblemente tener otro impacto no especificado insertando un dispositivo USB que carezca de un punto final de expansión.
Linux kernel version 3.10.0-229.20.1.el7.x86_64 crashes on presentation of a buggy USB device requiring the visor (clie_5_attach) driver.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2015-09-29 CVE Reserved
- 2016-01-19 CVE Published
- 2023-08-22 EPSS Updated
- 2024-08-06 CVE Updated
- 2024-08-06 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (27)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/archive/1/537733/100/0/threaded | Mailing List | |
http://www.securityfocus.com/bid/82975 | Vdb Entry | |
https://bugzilla.redhat.com/show_bug.cgi?id=1283371 | Issue Tracking | |
https://bugzilla.redhat.com/show_bug.cgi?id=1296466 | Issue Tracking | |
https://github.com/torvalds/linux/commit/cb3232138e37129e88240a98a1d2aba2187ff57c | X_refsource_confirm | |
https://security-tracker.debian.org/tracker/CVE-2015-7566 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/39540 | 2024-08-06 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Novell Search vendor "Novell" | Suse Linux Enterprise Software Development Kit Search vendor "Novell" for product "Suse Linux Enterprise Software Development Kit" | 11 Search vendor "Novell" for product "Suse Linux Enterprise Software Development Kit" and version "11" | sp4 |
Affected
| ||||||
Novell Search vendor "Novell" | Suse Linux Enterprise Debuginfo Search vendor "Novell" for product "Suse Linux Enterprise Debuginfo" | 11 Search vendor "Novell" for product "Suse Linux Enterprise Debuginfo" and version "11" | sp4 |
Affected
| ||||||
Novell Search vendor "Novell" | Suse Linux Enterprise Real Time Extension Search vendor "Novell" for product "Suse Linux Enterprise Real Time Extension" | 11 Search vendor "Novell" for product "Suse Linux Enterprise Real Time Extension" and version "11" | sp4 |
Affected
| ||||||
Novell Search vendor "Novell" | Suse Linux Enterprise Real Time Extension Search vendor "Novell" for product "Suse Linux Enterprise Real Time Extension" | 12 Search vendor "Novell" for product "Suse Linux Enterprise Real Time Extension" and version "12" | sp1 |
Affected
| ||||||
Novell Search vendor "Novell" | Suse Linux Enterprise Server Search vendor "Novell" for product "Suse Linux Enterprise Server" | 11 Search vendor "Novell" for product "Suse Linux Enterprise Server" and version "11" | extra |
Affected
| ||||||
Novell Search vendor "Novell" | Suse Linux Enterprise Server Search vendor "Novell" for product "Suse Linux Enterprise Server" | 11 Search vendor "Novell" for product "Suse Linux Enterprise Server" and version "11" | sp4 |
Affected
| ||||||
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | <= 4.4.1 Search vendor "Linux" for product "Linux Kernel" and version " <= 4.4.1" | - |
Affected
|