CVE-2016-5400

MEDIUM

Linux Kernel < 4.6.6 - Memory Corruption

Title source: rule

Description

Memory leak in the airspy_probe function in drivers/media/usb/airspy/airspy.c in the airspy USB driver in the Linux kernel before 4.7 allows local users to cause a denial of service (memory consumption) via a crafted USB device that emulates many VFL_TYPE_SDR or VFL_TYPE_SUBDEV devices and performs many connect and disconnect operations.

Scores

CVSS v3 4.3
EPSS 0.0008
EPSS Percentile 23.8%
Attack Vector PHYSICAL
CVSS:3.0/AV:P/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Classification

CWE
CWE-119
Status draft

Affected Products (1)

linux/linux_kernel < 4.6.6

Timeline

Published Aug 06, 2016
Tracked Since Feb 18, 2026