PT-2016-5776 · Linux+2 · Linux Kernel+2

Andrey Konovalov

·

Published

2016-05-02

·

Updated

2017-08-13

·

CVE-2016-3951

CVSS v2.0

4.9

Medium

VectorAV:L/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 4.5
Description A double free vulnerability in the Linux kernel allows physically proximate attackers to cause a denial of service, potentially leading to a system crash, by inserting a USB device with an invalid USB descriptor. The vulnerability is located in the drivers/net/usb/cdc ncm.c file.
Recommendations For Linux kernel versions prior to 4.5, update to version 4.5 or later to resolve the issue. As a temporary workaround, consider restricting access to USB devices to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2016-3951
DLA-516-1
DSA-3607-1
OPENSUSE-SU-2016_1382-1
OPENSUSE-SU-2016_2144-1
SUSE-SU-2016:1690-1
SUSE-SU-2016:1696-1
SUSE-SU-2016:1764-1
USN-2965-1
USN-2965-2
USN-2965-3
USN-2965-4
USN-2989-1
USN-2998-1
USN-3000-1
USN-3001-1
USN-3002-1
USN-3003-1
USN-3004-1
USN-3021-1
USN-3021-2

Affected Products

Linux Kernel
Suse
Ubuntu