Description

In the Linux kernel before 4.8, usb_parse_endpoint in drivers/usb/core/config.c does not validate the wMaxPacketSize field of an endpoint descriptor. NOTE: This vulnerability only affects products that are no longer supported by the supplier.

INFO

Published Date :

2024-06-27T00:00:00.000Z

Last Modified :

2025-03-13T17:18:45.868Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2016-20022 vulnerability.

Vendors Products
Linux
  • Linux Kernel

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact