CVE-2018-20961 PUBLISHED

In the Linux kernel before 4.16.4, a double free vulnerability in the f_midi_set_alt function of drivers/usb/gadget/function/f_midi.c in the f_midi driver may allow attackers to cause a denial of service or possibly have unspecified other impact.

EPSS 5.77% · 90.4th percentile

Risk Scores

EPSS Score
5.77%
90.4th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSlinux-gcp4.13.0-1006.9, 0, 4.10.0-1004.4
Ubuntu:Pro:FIPS:16.04:LTSlinux-fips4.4.0-1019.24, 0, 4.4.0-1003.3
Ubuntu:20.04:LTSlinux-riscv5.4.0-33.37, 5.4.0-40.45, 5.4.0-39.44
Ubuntu:16.04:LTSlinux-hwe4.13.0-36.40~16.04.1, 4.13.0-32.35~16.04.1, 4.13.0-31.34~16.04.1
Ubuntu:Pro:14.04:LTSlinux-lts-xenial4.4.0-62.83~14.04.1, 4.4.0-64.85~14.04.1, 4.4.0-66.87~14.04.1
Ubuntu:18.04:LTSlinux-raspi20, 4.15.0-1012.13, 4.15.0-1006.7
Ubuntu:18.04:LTSlinux-snapdragon0, 4.4.0-1077.82, 4.4.0-1078.83
Ubuntu:20.04:LTSlinux-gke5.4.0-1059.62, 5.4.0-1105.112, 5.4.0-1104.111
Ubuntu:22.04:LTSlinux-realtime5.15.0-1032.35, 0
Ubuntu:18.04:LTSlinux4.15.0-23.25, 4.15.0-15.16, 4.15.0-13.14
Ubuntu:16.04:LTSlinux-snapdragon4.4.0-1058.62, 4.4.0-1057.61, 4.4.0-1055.59
Ubuntu:18.04:LTSlinux-gcp0, 4.15.0-1001.1, 4.15.0-1003.3
Ubuntu:16.04:LTSlinux4.4.0-42.62, 0, 4.2.0-16.19
Ubuntu:22.04:LTSlinux-riscv5.15.0-1014.16, 5.15.0-1012.13, 5.15.0-1011.12
Ubuntu:24.04:LTSlinux-raspi-realtime6.8.0-2019.20, 0
Ubuntu:18.04:LTSlinux-oem4.15.0-1002.3, 4.15.0-1004.5, 4.15.0-1008.11
Ubuntu:22.04:LTSlinux-intel-iot-realtime5.15.0-1073.75, 0
Ubuntu:20.04:LTSlinux-raspi20, 5.3.0-1015.17, 5.3.0-1017.19
Ubuntu:Pro:14.04:LTSlinux-aws4.4.0-1006.6, 0, 4.4.0-1054.58
Ubuntu:16.04:LTSlinux-raspi24.4.0-1027.33, 4.4.0-1120.129, 4.4.0-1118.127

…and 1 more

Timeline

References

Open in Interactive Console →