CVE-2016-4482
Severity
6.2MEDIUM
EPSS
0.0%
top 89.79%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 23
Latest updateMay 17
Description
The proc_connectinfo function in drivers/usb/core/devio.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via a crafted USBDEVFS_CONNECTINFO ioctl call.
CVSS vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.5 | Impact: 3.6
Affected Packages10 packages
Also affects: Ubuntu Linux 12.04, 14.04, 15.10, 16.04, Fedora 24
🔴Vulnerability Details
9📋Vendor Advisories
14Android▶
CVE-2016-4482: Android Security Bulletin 2016-08-01
CVE: CVE-2016-4482
Severity: HIGH
References: A-28619695
Upstream kernel↗2016-08-01