CVE-2016-3136 | Linux Kernel up to 4.5.0 USB Device mct_u232.c mct_u232_msr_to_state null pointer dereference (FEDORA-2016-81fd1b03aa / EDB-39541)
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 4.5.0. Affected by this issue is the function mct_u232_msr_to_state of the file drivers/usb/serial/mct_u232.c of the component USB Device Handler. The manipulation leads to null pointer dereference.
This vulnerability is handled as CVE-2016-3136. It is possible to launch the attack on the local host. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.