The gtco_probe function in drivers/input/tablet/gtco.c in the Linux kernel through 4.5.2 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB device descriptor.
| Software | From | Fixed in |
|---|---|---|
| canonical / ubuntu_linux | 12.04 | 12.04.x |
| canonical / ubuntu_linux | 16.04 | 16.04.x |
| canonical / ubuntu_linux | 15.10 | 15.10.x |
| canonical / ubuntu_linux | 14.04 | 14.04.x |
| linux / linux_kernel | - | 4.5.2.x |
| novell / suse_linux_enterprise_server | 11-sp4 | 11-sp4.x |
| novell / suse_linux_enterprise_debuginfo | 11-sp4 | 11-sp4.x |
| novell / suse_linux_enterprise_server | 11-extra | 11-extra.x |
| novell / suse_linux_enterprise_software_development_kit | 11.0-sp4 | 11.0-sp4.x |