CVE-2017-16525 PUBLISHED

The usb_serial_console_disconnect function in drivers/usb/serial/console.c in the Linux kernel before 4.13.8 allows local users to cause a denial of service (use-after-free and system crash) or possibly have unspecified other impact via a crafted USB device, related to disconnection and failed setup.

EPSS 0.10% · 28.3th percentile

Risk Scores

EPSS Score
0.10%
28.3th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSlinux-gcp4.10.0-1004.4, 0, 4.10.0-1009.9
Ubuntu:24.04:LTSlinux-raspi-realtime6.8.0-2019.20, 0
Ubuntu:16.04:LTSlinux-aws4.4.0-1011.20, 4.4.0-1012.21, 4.4.0-1013.22
Ubuntu:14.04:LTSlinux3.13.0-41.70, 3.13.0-43.72, 3.13.0-44.73
Ubuntu:16.04:LTSlinux-gke4.4.0-1032.32, 4.4.0-1031.31, 4.4.0-1028.28
Ubuntu:20.04:LTSlinux-azure-fde0, 5.4.0-1063.66+cvm2.2, 5.4.0-1063.66+cvm3.2
Ubuntu:20.04:LTSlinux-gke5.4.0-1084.90, 0, 5.4.0-1033.35
Ubuntu:16.04:LTSlinux-azure4.11.0-1015.15, 4.11.0-1016.16, 0
Ubuntu:22.04:LTSlinux-riscv5.15.0-1020.23, 5.15.0-1019.22, 5.15.0-1018.21
Ubuntu:16.04:LTSlinux-raspi24.4.0-1040.47, 4.4.0-1038.45, 4.4.0-1034.41
Ubuntu:16.04:LTSlinux-snapdragon4.4.0-1058.62, 4.4.0-1061.66, 4.4.0-1063.68
Ubuntu:20.04:LTSlinux-raspi25.3.0-1015.17, 0, 5.3.0-1007.8
Ubuntu:20.04:LTSlinux-riscv5.4.0-34.38, 5.4.0-37.42, 5.4.0-39.44
Ubuntu:22.04:LTSlinux-realtime5.15.0-1032.35, 0
Ubuntu:22.04:LTSlinux-intel-iot-realtime5.15.0-1073.75, 0
Ubuntu:16.04:LTSlinux-hwe0, 4.8.0-36.36~16.04.1, 4.8.0-39.42~16.04.1
Ubuntu:16.04:LTSlinux-kvm4.4.0-1004.9, 0, 4.4.0-1008.13
Ubuntu:14.04:LTSlinux-aws4.4.0-1002.2, 0
Ubuntu:14.04:LTSlinux-lts-xenial4.4.0-64.85~14.04.1, 4.4.0-66.87~14.04.1, 4.4.0-67.88~14.04.1
Ubuntu:16.04:LTSlinux4.4.0-28.47, 4.4.0-24.43, 4.4.0-22.40

Timeline

References

Open in Interactive Console →