CVE-2015-7566
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 1.8%
from disclosure to weapon30 days
Published on NVDFeb 8
1st PoC+30d
exploitation probability
1.8%top 23% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
The clie_5_attach function in drivers/usb/serial/visor.c in the Linux kernel through 4.4.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by inserting a USB device that lacks a bulk-out endpoint.
Affected products
n/a · n/apublic PoCs found — 2
exploitdbwww.exploit-db.com/exploits/39540unverifiedcve_referencewww.exploit-db.com/exploits/39540/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=cb3232138e37129e88240a98a1d2aba2187ff57chttp://lists.fedoraproject.org/pipermail/package-announce/2016-February/176484.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-January/175792.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-January/176194.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00052.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00059.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-07/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00038.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1283371https://bugzilla.redhat.com/show_bug.cgi?id=1296466https://github.com/torvalds/linux/commit/cb3232138e37129e88240a98a1d2aba2187ff57chttps://security-tracker.debian.org/tracker/CVE-2015-7566