CVE-2015-7515 describes a NULL pointer dereference vulnerability in the aiptek_probe function of the Linux kernel (versions prior to 4.4), specifically impacting the aiptek.c driver. This flaw allows a physically proximate attacker to trigger a system crash and denial of service by connecting a specially crafted USB device lacking endpoints. With a CVSS score of 4.6 (Medium), exploitation requires physical access and has low attack complexity, resulting in high availability impact but no confidentiality or integrity compromise. While there is an ExploitDB entry (EDB-39544) demonstrating a proof-of-concept for specific Linux kernel versions, there is no evidence of active exploitation, Metasploit modules, or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.4CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
4.4CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:4.4:rc1:*:*:*:*:*:* | ||
4.4CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:4.4:rc2:*:*:*:*:*:* | ||
4.4CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:4.4:rc3:*:*:*:*:*:* | ||
4.4CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:4.4:rc4:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.