drivers/usb/serial/cypress_m8.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a USB device without both an interrupt-in and an interrupt-out endpoint descriptor, related to the cypress_generic_port_probe and cypress_open functions.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3137
Reference (s):
- BID:84300
- URL: http://www.securityfocus.com/bid/84300
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=c55aee1bf0e6b6feec8b2927b43f7a09a6d5f754
- http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.5.1
- https://bugzilla.redhat.com/show_bug.cgi?id=1316996

