In the Linux kernel before 4.8, usbparseendpoint in drivers/usb/core/config.c does not validate the wMaxPacketSize field of an endpoint descriptor. NOTE: This vulnerability only affects products that are no longer supported by the supplier.
{ "extracted_events": [ { "introduced": "0" }, { "fixed": "4.8" } ], "source": "DESCRIPTION" }
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-20022.json"