CVE-2016-5400 PUBLISHED

Memory leak in the airspy_probe function in drivers/media/usb/airspy/airspy.c in the airspy USB driver in the Linux kernel before 4.7 allows local users to cause a denial of service (memory consumption) via a crafted USB device that emulates many VFL_TYPE_SDR or VFL_TYPE_SUBDEV devices and performs many connect and disconnect operations.

EPSS 0.08% · 24.0th percentile

Risk Scores

EPSS Score
0.08%
24.0th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSlinux-snapdragon4.4.0-1013.15, 4.4.0-1013.14, 4.4.0-1012.12
Ubuntu:16.04:LTSlinux-raspi24.4.0-1004.5, 4.4.0-1003.4, 4.3.0-1006.6
Ubuntu:16.04:LTSlinux4.4.0-10.25, 0, 4.2.0-16.19
Ubuntu:14.04:LTSlinux-lts-xenial4.4.0-28.47~14.04.1, 4.4.0-31.50~14.04.1, 4.4.0-34.53~14.04.1
Ubuntu:14.04:LTSlinux-lts-vivid3.19.0-30.34~14.04.1, 3.19.0-51.58~14.04.1, 3.19.0-56.62~14.04.1

Timeline

References

Open in Interactive Console →