The treo_attach function in drivers/usb/serial/visor.c in the Linux kernel before 4.5 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by inserting a USB device that lacks a (1) bulk-in or (2) interrupt-in endpoint.
2016-04-27T17:59:20.960
2025-04-12T10:46:40.837
Deferred
CVSSv3.1: 4.6 (MEDIUM)
AV:L/AC:L/Au:N/C:N/I:N/A:C
3.9
6.9