CVE-2016-3139

Published on: 04/27/2016 12:00:00 AM UTC

Last Modified on: 03/23/2021 11:27:02 PM UTC

CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Certain versions of Linux Kernel from Linux contain the following vulnerability:

The wacom_probe function in drivers/input/tablet/wacom_sys.c in the Linux kernel before 3.17 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB device descriptor.

  • CVE-2016-3139 has been assigned by URL Logo [email protected] to track the vulnerability - currently rated as MEDIUM severity.

CVSS3 Score: 4.6 - MEDIUM

Attack
Vector
Attack
Complexity
Privileges
Required
User
Interaction
PHYSICAL LOW NONE NONE
Scope Confidentiality
Impact
Integrity
Impact
Availability
Impact
UNCHANGED NONE NONE HIGH

CVSS2 Score: 4.9 - MEDIUM

Access
Vector
Access
Complexity
Authentication
LOCAL LOW NONE
Confidentiality
Impact
Integrity
Impact
Availability
Impact
NONE NONE COMPLETE

CVE References

Description Tags Link
Input: wacom - move the USB (now hid) Wacom driver in drivers/hid · torvalds/[email protected] · GitHub Patch
Vendor Advisory
github.com
text/html
URL Logo MISC github.com/torvalds/linux/commit/471d17148c8b4174ac5f5283a73316d12c4379bc
[security-announce] SUSE-SU-2016:1707-1: important: Security update for Third Party Advisory
lists.opensuse.org
text/html
URL Logo SUSE SUSE-SU-2016:1707
Linux Kernel 3.10.0 (CentOS / RHEL 7.1) - 'Wacom' Multiple Nullpointer Dereferences - Linux dos Exploit www.exploit-db.com
Proof of Concept
text/html
URL Logo EXPLOIT-DB 39538
[security-announce] SUSE-SU-2016:2074-1: important: Security update for lists.opensuse.org
text/html
URL Logo SUSE SUSE-SU-2016:2074
CVE-2016-3139 Third Party Advisory
VDB Entry
security-tracker.debian.org
text/html
URL Logo CONFIRM security-tracker.debian.org/tracker/CVE-2016-3139
kernel/git/torvalds/linux.git - Linux kernel source tree git.kernel.org
text/html
URL Logo MISC git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=471d17148c8b4174ac5f5283a73316d12c4379bc
[security-announce] SUSE-SU-2016:1672-1: important: Security update for Third Party Advisory
lists.opensuse.org
text/html
URL Logo SUSE SUSE-SU-2016:1672
Bug 1283375 – CVE-2016-3139 Local RedHat Enterprise Linux DoS – RHEL 7.1 Kernel crashes on invalid USB device descriptors (wacom driver) [local-DoS] Issue Tracking
Third Party Advisory
VDB Entry
bugzilla.redhat.com
text/html
URL Logo CONFIRM bugzilla.redhat.com/show_bug.cgi?id=1283375
1316993 – (CVE-2016-3139) CVE-2016-3139 kernel: Crash on invalid USB device descriptors (wacom driver) Issue Tracking
Third Party Advisory
VDB Entry
bugzilla.redhat.com
text/html
URL Logo CONFIRM bugzilla.redhat.com/show_bug.cgi?id=1316993
[security-announce] SUSE-SU-2016:1764-1: important: Security update for Third Party Advisory
lists.opensuse.org
text/html
URL Logo SUSE SUSE-SU-2016:1764
[security-announce] SUSE-SU-2016:1690-1: important: Security update for Third Party Advisory
lists.opensuse.org
text/html
URL Logo SUSE SUSE-SU-2016:1690
[security-announce] SUSE-SU-2016:1019-1: important: Security update for lists.opensuse.org
text/html
URL Logo SUSE SUSE-SU-2016:1019
Bug 1283377 – CVE-2016-3139 Local RedHat Enterprise Linux DoS – RHEL 7.1 Kernel crashes on invalid USB device descriptors (wacom driver) [local-DoS] Bug2 Issue Tracking
Third Party Advisory
VDB Entry
bugzilla.redhat.com
text/html
URL Logo CONFIRM bugzilla.redhat.com/show_bug.cgi?id=1283377

Known Affected Configurations (CPE V2.3)

Type Vendor Product Version Update Edition Language
Operating
System
LinuxLinux KernelAllAllAllAll
Operating
System
NovellSuse Linux Enterprise Debuginfo11.0sp4AllAll
Operating
System
NovellSuse Linux Enterprise Debuginfo11.0sp4AllAll
Operating
System
NovellSuse Linux Enterprise Desktop12.0AllAllAll
Operating
System
NovellSuse Linux Enterprise Desktop12.0AllAllAll
Operating
System
NovellSuse Linux Enterprise Live Patching12.0AllAllAll
Operating
System
NovellSuse Linux Enterprise Live Patching12.0AllAllAll
Operating
System
NovellSuse Linux Enterprise Module For Public Cloud12.0AllAllAll
Operating
System
NovellSuse Linux Enterprise Module For Public Cloud12.0AllAllAll
Operating
System
NovellSuse Linux Enterprise Real Time Extension11.0sp4AllAll
Operating
System
NovellSuse Linux Enterprise Real Time Extension12.0sp1AllAll
Operating
System
NovellSuse Linux Enterprise Real Time Extension11.0sp4AllAll
Operating
System
NovellSuse Linux Enterprise Real Time Extension12.0sp1AllAll
Operating
System
NovellSuse Linux Enterprise Server11.0extraAllAll
Operating
System
NovellSuse Linux Enterprise Server11.0sp4AllAll
Operating
System
NovellSuse Linux Enterprise Server12.0AllAllAll
Operating
System
NovellSuse Linux Enterprise Server11.0extraAllAll
Operating
System
NovellSuse Linux Enterprise Server11.0sp4AllAll
Operating
System
NovellSuse Linux Enterprise Server12.0AllAllAll
Operating
System
NovellSuse Linux Enterprise Software Development Kit11.0sp4AllAll
Operating
System
NovellSuse Linux Enterprise Software Development Kit12.0AllAllAll
Operating
System
NovellSuse Linux Enterprise Software Development Kit11.0sp4AllAll
Operating
System
NovellSuse Linux Enterprise Software Development Kit12.0AllAllAll
Operating
System
NovellSuse Linux Enterprise Workstation Extension12.0AllAllAll
Operating
System
NovellSuse Linux Enterprise Workstation Extension12.0AllAllAll
  • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*:
  • cpe:2.3:o:novell:suse_linux_enterprise_debuginfo:11.0:sp4:*:*:*:*:*:*:
  • cpe:2.3:o:novell:suse_linux_enterprise_debuginfo:11.0:sp4:*:*:*:*:*:*:
  • cpe:2.3:o:novell:suse_linux_enterprise_desktop:12.0:*:*:*:*:*:*:*:
  • cpe:2.3:o:novell:suse_linux_enterprise_desktop:12.0:*:*:*:*:*:*:*:
  • cpe:2.3:o:novell:suse_linux_enterprise_live_patching:12.0:*:*:*:*:*:*:*:
  • cpe:2.3:o:novell:suse_linux_enterprise_live_patching:12.0:*:*:*:*:*:*:*:
  • cpe:2.3:o:novell:suse_linux_enterprise_module_for_public_cloud:12.0:*:*:*:*:*:*:*:
  • cpe:2.3:o:novell:suse_linux_enterprise_module_for_public_cloud:12.0:*:*:*:*:*:*:*:
  • cpe:2.3:o:novell:suse_linux_enterprise_real_time_extension:11.0:sp4:*:*:*:*:*:*:
  • cpe:2.3:o:novell:suse_linux_enterprise_real_time_extension:12.0:sp1:*:*:*:*:*:*:
  • cpe:2.3:o:novell:suse_linux_enterprise_real_time_extension:11.0:sp4:*:*:*:*:*:*:
  • cpe:2.3:o:novell:suse_linux_enterprise_real_time_extension:12.0:sp1:*:*:*:*:*:*:
  • cpe:2.3:o:novell:suse_linux_enterprise_server:11.0:extra:*:*:*:*:*:*:
  • cpe:2.3:o:novell:suse_linux_enterprise_server:11.0:sp4:*:*:*:*:*:*:
  • cpe:2.3:o:novell:suse_linux_enterprise_server:12.0:*:*:*:*:*:*:*:
  • cpe:2.3:o:novell:suse_linux_enterprise_server:11.0:extra:*:*:*:*:*:*:
  • cpe:2.3:o:novell:suse_linux_enterprise_server:11.0:sp4:*:*:*:*:*:*:
  • cpe:2.3:o:novell:suse_linux_enterprise_server:12.0:*:*:*:*:*:*:*:
  • cpe:2.3:o:novell:suse_linux_enterprise_software_development_kit:11.0:sp4:*:*:*:*:*:*:
  • cpe:2.3:o:novell:suse_linux_enterprise_software_development_kit:12.0:*:*:*:*:*:*:*:
  • cpe:2.3:o:novell:suse_linux_enterprise_software_development_kit:11.0:sp4:*:*:*:*:*:*:
  • cpe:2.3:o:novell:suse_linux_enterprise_software_development_kit:12.0:*:*:*:*:*:*:*:
  • cpe:2.3:o:novell:suse_linux_enterprise_workstation_extension:12.0:*:*:*:*:*:*:*:
  • cpe:2.3:o:novell:suse_linux_enterprise_workstation_extension:12.0:*:*:*:*:*:*:*: