CVE-2016-7912 PUBLISHED

Use-after-free vulnerability in the ffs_user_copy_worker function in drivers/usb/gadget/function/f_fs.c in the Linux kernel before 4.5.3 allows local users to gain privileges by accessing an I/O data structure after a certain callback call.

EPSS 0.27% · 50.1th percentile

Risk Scores

EPSS Score
0.27%
50.1th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSlinux-snapdragon0, 4.4.0-1013.15, 4.4.0-1013.14
Ubuntu:16.04:LTSlinux0, 4.2.0-16.19, 4.2.0-17.21
Ubuntu:14.04:LTSlinux-lts-xenial4.4.0-22.39~14.04.1, 4.4.0-13.29~14.04.1, 4.4.0-14.30~14.04.2
Ubuntu:16.04:LTSlinux-raspi24.4.0-1003.4, 4.4.0-1004.5, 4.4.0-1009.10

Timeline

References

Open in Interactive Console →