CVE-2016-4482

Severity
6.2MEDIUM
EPSS
0.0%
top 89.79%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 23
Latest updateMay 17

Description

The proc_connectinfo function in drivers/usb/core/devio.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via a crafted USBDEVFS_CONNECTINFO ioctl call.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.5 | Impact: 3.6

Affected Packages10 packages

Also affects: Ubuntu Linux 12.04, 14.04, 15.10, 16.04, Fedora 24

🔴Vulnerability Details

9
GHSA
GHSA-jq2w-vr89-j383: The proc_connectinfo function in drivers/usb/core/devio2022-05-17
OSV
linux-lts-vivid vulnerabilities2016-06-27
OSV
linux-snapdragon vulnerabilities2016-06-27
OSV
linux-lts-utopic vulnerabilities2016-06-27
OSV
linux-raspi2 vulnerabilities2016-06-27

📋Vendor Advisories

14
Android
CVE-2016-4482: Android Security Bulletin 2016-08-01 CVE: CVE-2016-4482 Severity: HIGH References: A-28619695 Upstream kernel2016-08-01
Ubuntu
Linux kernel (Wily HWE) vulnerabilities2016-06-27
Ubuntu
Linux kernel vulnerabilities2016-06-27
Ubuntu
Linux kernel (Vivid HWE) vulnerabilities2016-06-27
Ubuntu
Linux kernel (OMAP4) vulnerabilities2016-06-27

💬Community

2
Bugzilla
CVE-2016-4482 kernel: information leak in devio.c2016-05-04
Bugzilla
CVE-2016-4482 kernel: information leak in devio.c [fedora-all]2016-05-04