CVE-2016-3139
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 1.8%
from disclosure to weapon0 days
Published on NVDApr 27
1st PoCMar 9
exploitation probability
1.8%top 24% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
The wacom_probe function in drivers/input/tablet/wacom_sys.c in the Linux kernel before 3.17 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB device descriptor.
Affected products
n/a · n/apublic PoCs found — 2
cve_referencewww.exploit-db.com/exploits/39538/unverifiedexploitdbwww.exploit-db.com/exploits/39538unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=471d17148c8b4174ac5f5283a73316d12c4379bchttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00019.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00052.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00054.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00059.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-07/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00038.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1283375https://bugzilla.redhat.com/show_bug.cgi?id=1283377https://bugzilla.redhat.com/show_bug.cgi?id=1316993https://github.com/torvalds/linux/commit/471d17148c8b4174ac5f5283a73316d12c4379bchttps://security-tracker.debian.org/tracker/CVE-2016-3139