CVE-2016-2782 is a NULL pointer dereference vulnerability in the Linux kernel's treo_attach function (drivers/usb/serial/visor.c), affecting Linux and SUSE distributions. A physically proximate attacker can trigger a system crash (Denial of Service) by inserting a USB device lacking a bulk-in or interrupt-in endpoint. With a CVSS score of 4.6 (Medium), this vulnerability requires physical access and has a high impact on availability. While not listed on the KEV catalog and with no Metasploit or Nuclei modules, an ExploitDB entry (EDB-39539) exists, indicating proof-of-concept code for CentOS/RHEL 7.1. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.5.0CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
4.5.0CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:4.5.0:rc1:*:*:*:*:*:* | ||
11CPE matchmatch criteria | cpe:2.3:a:suse:linux_enterprise_debuginfo:11:sp2:*:*:*:*:*:* | ||
11CPE matchmatch criteria | cpe:2.3:a:suse:linux_enterprise_debuginfo:11:sp4:*:*:*:*:*:* | ||
12CPE matchmatch criteria | cpe:2.3:a:suse:linux_enterprise_module_for_public_cloud:12:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.