The treo_attach function in drivers/usb/serial/visor.c in the Linux kernel before 4.5 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by inserting a USB device that lacks a (1) bulk-in or (2) interrupt-in endpoint.
{
"unresolved_ranges": [
{
"cpe": "cpe:2.3:a:suse:linux_enterprise_debuginfo:11:sp2:*:*:*:*:*:*",
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "11-sp2"
}
]
},
{
"cpe": "cpe:2.3:a:suse:linux_enterprise_debuginfo:11:sp4:*:*:*:*:*:*",
"extracted_events": [
{
"last_affected": "11-sp4"
}
],
"source": "CPE_FIELD"
},
{
"cpe": "cpe:2.3:a:suse:linux_enterprise_module_for_public_cloud:12:*:*:*:*:*:*:*",
"extracted_events": [
{
"last_affected": "12"
}
],
"source": "CPE_FIELD"
},
{
"cpe": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"source": "CPE_FIELD",
"extracted_events": [
{
"fixed": "4.5.0"
}
]
},
{
"cpe": "cpe:2.3:o:linux:linux_kernel:4.5.0:rc1:*:*:*:*:*:*",
"extracted_events": [
{
"last_affected": "4.5.0-rc1"
}
],
"source": "CPE_FIELD"
},
{
"cpe": "cpe:2.3:o:suse:linux_enterprise_desktop:12:-:*:*:*:*:*:*",
"extracted_events": [
{
"last_affected": "12-NA"
}
],
"source": "CPE_FIELD"
},
{
"cpe": "cpe:2.3:o:suse:linux_enterprise_desktop:12:sp1:*:*:*:*:*:*",
"extracted_events": [
{
"last_affected": "12-sp1"
}
],
"source": "CPE_FIELD"
},
{
"cpe": "cpe:2.3:o:suse:linux_enterprise_real_time_extension:11:sp4:*:*:*:*:*:*",
"extracted_events": [
{
"last_affected": "11-sp4"
}
],
"source": "CPE_FIELD"
},
{
"cpe": "cpe:2.3:o:suse:linux_enterprise_real_time_extension:12:sp1:*:*:*:*:*:*",
"extracted_events": [
{
"last_affected": "12-sp1"
}
],
"source": "CPE_FIELD"
},
{
"cpe": "cpe:2.3:o:suse:linux_enterprise_server:11:sp2:*:*:ltss:*:*:*",
"extracted_events": [
{
"last_affected": "11-sp2"
}
],
"source": "CPE_FIELD"
},
{
"cpe": "cpe:2.3:o:suse:linux_enterprise_server:11:sp4:*:*:*:*:*:*",
"extracted_events": [
{
"last_affected": "11-sp4"
}
],
"source": "CPE_FIELD"
},
{
"cpe": "cpe:2.3:o:suse:linux_enterprise_server:12:-:*:*:*:*:*:*",
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "12-NA"
}
]
},
{
"cpe": "cpe:2.3:o:suse:linux_enterprise_server:12:sp1:*:*:*:*:*:*",
"extracted_events": [
{
"last_affected": "12-sp1"
}
],
"source": "CPE_FIELD"
},
{
"cpe": "cpe:2.3:o:suse:linux_enterprise_software_development_kit:11:sp4:*:*:*:*:*:*",
"extracted_events": [
{
"last_affected": "11-sp4"
}
],
"source": "CPE_FIELD"
},
{
"cpe": "cpe:2.3:o:suse:linux_enterprise_software_development_kit:12:-:*:*:*:*:*:*",
"extracted_events": [
{
"last_affected": "12-NA"
}
],
"source": "CPE_FIELD"
},
{
"cpe": "cpe:2.3:o:suse:linux_enterprise_software_development_kit:12:sp1:*:*:*:*:*:*",
"extracted_events": [
{
"last_affected": "12-sp1"
}
],
"source": "CPE_FIELD"
},
{
"cpe": "cpe:2.3:o:suse:linux_enterprise_workstation_extension:12:*:*:*:*:*:*:*",
"extracted_events": [
{
"last_affected": "12"
}
],
"source": "CPE_FIELD"
},
{
"cpe": "cpe:2.3:o:suse:linux_enterprise_workstation_extension:12:sp1:*:*:*:*:*:*",
"extracted_events": [
{
"last_affected": "12-sp1"
}
],
"source": "CPE_FIELD"
}
]
}{
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "4.5"
}
],
"source": [
"DESCRIPTION",
"REFERENCES"
]
}