Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-20022

Опубликовано: 27 июн. 2024
Источник: debian

Описание

In the Linux kernel before 4.8, usb_parse_endpoint in drivers/usb/core/config.c does not validate the wMaxPacketSize field of an endpoint descriptor. NOTE: This vulnerability only affects products that are no longer supported by the supplier.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
linuxfixed4.7.4-1package

Примечания

  • https://git.kernel.org/linus/aed9d65ac3278d4febd8665bd7db59ef53e825fe (4.8-rc3)

Связанные уязвимости

CVSS3: 8.4
ubuntu
больше 1 года назад

In the Linux kernel before 4.8, usb_parse_endpoint in drivers/usb/core/config.c does not validate the wMaxPacketSize field of an endpoint descriptor. NOTE: This vulnerability only affects products that are no longer supported by the supplier.

CVSS3: 6.2
redhat
больше 1 года назад

In the Linux kernel before 4.8, usb_parse_endpoint in drivers/usb/core/config.c does not validate the wMaxPacketSize field of an endpoint descriptor. NOTE: This vulnerability only affects products that are no longer supported by the supplier.

CVSS3: 8.4
nvd
больше 1 года назад

In the Linux kernel before 4.8, usb_parse_endpoint in drivers/usb/core/config.c does not validate the wMaxPacketSize field of an endpoint descriptor. NOTE: This vulnerability only affects products that are no longer supported by the supplier.

CVSS3: 8.4
github
больше 1 года назад

In the Linux kernel before 4.8, usb_parse_endpoint in drivers/usb/core/config.c does not validate the wMaxPacketSize field of an endpoint descriptor. NOTE: This vulnerability only affects products that are no longer supported by the supplier.

CVSS3: 8.4
fstec
больше 9 лет назад

Уязвимость функции usb_parse_ss_endpoint_companion() модуля drivers/usb/core/config.c драйвера поддержки устройств шины USB ядра операционной системы Linux, позволяющая нарушителю вызвать отказ в обслуживании.