CVE-2016-3955

CRITICAL

Linux Kernel < 4.5.3 - Denial of Service via USB/IP Packet Length Mismatch

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2016-3955. PoCs published by pqsec.

AI-analyzed exploit summary This repository contains a Go-based demo server that exploits CVE-2016-3955, a Linux heap buffer overflow in USB/IP. The server emulates a USB device and triggers the overflow by sending a crafted URB response with an inflated buffer length.

Description

The usbip_recv_xbuff function in drivers/usb/usbip/usbip_common.c in the Linux kernel before 4.5.3 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via a crafted length value in a USB/IP packet.

Exploits (1)

nomisec WORKING POC 4 stars
by pqsec · poc
https://github.com/pqsec/uboatdemo

This repository contains a Go-based demo server that exploits CVE-2016-3955, a Linux heap buffer overflow in USB/IP. The server emulates a USB device and triggers the overflow by sending a crafted URB response with an inflated buffer length.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Linux kernel USB/IP subsystem (versions affected by CVE-2016-3955)
No auth needed
Prerequisites: USB/IP client connection to the demo server · Linux kernel vulnerable to CVE-2016-3955
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (17)

Core 17
Core References
Third Party Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-3004-1
Third Party Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-3001-1
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00044.html
Third Party Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2997-1
Third Party Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-3000-1
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2016/dsa-3607
Third Party Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-3002-1
Third Party Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2996-1
Issue Tracking, Third Party Advisory x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=1328478
Third Party Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2989-1
Third Party Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-3003-1
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/86534
Third Party Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2998-1
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2016/04/19/1

Scores

CVSS v3 9.8
EPSS 0.1280
EPSS Percentile 94.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-119
Status published
Products (5)
canonical/ubuntu_linux 12.04 (2 CPE variants)
canonical/ubuntu_linux 14.04 (2 CPE variants)
canonical/ubuntu_linux 15.10
debian/debian_linux 8.0
linux/linux_kernel < 3.2.80
Published Jul 03, 2016
Tracked Since Feb 18, 2026