CVE-2016-5400
published 2016-08-06CVE-2016-5400: Memory leak in the airspy_probe function in drivers/media/usb/airspy/airspy.c in the airspy USB driver in the Linux kernel before 4.7 allows local users to…
PriorityP414medium4.3CVSS 3.0
AVPACLPRLUINSUCNINAH
EPSS
0.37%
30.4th percentile
Memory leak in the airspy_probe function in drivers/media/usb/airspy/airspy.c in the airspy USB driver in the Linux kernel before 4.7 allows local users to cause a denial of service (memory consumption) via a crafted USB device that emulates many VFL_TYPE_SDR or VFL_TYPE_SUBDEV devices and performs many connect and disconnect operations.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.7.2-1 (bookworm) | linux 4.7.2-1 (bookworm) |
| linux | linux_kernel | <= 4.6.6 | — |
| linux | linux_kernel | >= 0 < 4.7.2-1 | 4.7.2-1 |
| linux | linux_kernel | >= 0 < 4.7.2-1 | 4.7.2-1 |
| linux | linux_kernel | >= 0 < 4.7.2-1 | 4.7.2-1 |
| linux | linux_kernel | >= 0 < 4.7.2-1 | 4.7.2-1 |
| linux | linux_kernel | >= 0 < 4.4.0-36.55 | 4.4.0-36.55 |
CVSS provenance
nvdv3.04.3MEDIUMCVSS:3.0/AV:P/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv5.5MEDIUM
vendor_ubuntu5.5MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (Raspberry Pi 2) vulnerabilities
vendor_ubuntu·2016-08-30·CVSS 5.5
CVE-2016-1237 [MEDIUM] Linux kernel (Raspberry Pi 2) vulnerabilities
Title: Linux kernel (Raspberry Pi 2) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A missing permission check when settings ACLs was discovered in nfsd. A
local user could exploit this flaw to gain access to any file by setting an
ACL. (CVE-2016-1237)
Kangjie Lu discovered an information leak in the Reliable Datagram Sockets
(RDS) implementation in the Linux kernel. A local attacker could use this
to obtain potentially sensitive information from kernel memory.
(CVE-2016-5244)
James Patrick-Evans discovered that the airspy USB device driver in the
Linux kernel did not properly handle certain error conditions. An attacker
with physical access could use this to cause a denial of service (memory
consumption). (CVE-2016-5400)
Yue Cao et al discovered a flaw in
Ubuntu
Linux kernel (Qualcomm Snapdragon) vulnerabilities
vendor_ubuntu·2016-08-30·CVSS 5.5
CVE-2016-1237 [MEDIUM] Linux kernel (Qualcomm Snapdragon) vulnerabilities
Title: Linux kernel (Qualcomm Snapdragon) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A missing permission check when settings ACLs was discovered in nfsd. A
local user could exploit this flaw to gain access to any file by setting an
ACL. (CVE-2016-1237)
Kangjie Lu discovered an information leak in the Reliable Datagram Sockets
(RDS) implementation in the Linux kernel. A local attacker could use this
to obtain potentially sensitive information from kernel memory.
(CVE-2016-5244)
James Patrick-Evans discovered that the airspy USB device driver in the
Linux kernel did not properly handle certain error conditions. An attacker
with physical access could use this to cause a denial of service (memory
consumption). (CVE-2016-5400)
Yue Cao et al discovered a fla
Ubuntu
Linux kernel (Xenial HWE) vulnerabilities
vendor_ubuntu·2016-08-30·CVSS 5.5
CVE-2016-1237 [MEDIUM] Linux kernel (Xenial HWE) vulnerabilities
Title: Linux kernel (Xenial HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
USN-3070-1 fixed vulnerabilities in the Linux kernel for Ubuntu
16.04 LTS. This update provides the corresponding updates for the
Linux Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for
Ubuntu 14.04 LTS.
A missing permission check when settings ACLs was discovered in nfsd. A
local user could exploit this flaw to gain access to any file by setting an
ACL. (CVE-2016-1237)
Kangjie Lu discovered an information leak in the Reliable Datagram Sockets
(RDS) implementation in the Linux kernel. A local attacker could use this
to obtain potentially sensitive information from kernel memory.
(CVE-2016-5244)
James Patrick-Evans discovered that the airspy USB device driver in the
Linu
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2016-08-29·CVSS 5.5
CVE-2016-1237 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
A missing permission check when settings ACLs was discovered in nfsd. A
local user could exploit this flaw to gain access to any file by setting an
ACL. (CVE-2016-1237)
Kangjie Lu discovered an information leak in the Reliable Datagram Sockets
(RDS) implementation in the Linux kernel. A local attacker could use this
to obtain potentially sensitive information from kernel memory.
(CVE-2016-5244)
James Patrick-Evans discovered that the airspy USB device driver in the
Linux kernel did not properly handle certain error conditions. An attacker
with physical access could use this to cause a denial of service (memory
consumption). (CVE-2016-5400)
Yue Cao et al discovered a flaw in the TCP implement
Red Hat
kernel: memory leak in airspy usb driver
vendor_redhat·2016-07-20·CVSS 4.3
CVE-2016-5400 [MEDIUM] CWE-401 kernel: memory leak in airspy usb driver
kernel: memory leak in airspy usb driver
Memory leak in the airspy_probe function in drivers/media/usb/airspy/airspy.c in the airspy USB driver in the Linux kernel before 4.7 allows local users to cause a denial of service (memory consumption) via a crafted USB device that emulates many VFL_TYPE_SDR or VFL_TYPE_SUBDEV devices and performs many connect and disconnect operations.
A flaw was found in the linux kernel's implementation of the airspy USB device driver in which a leak was found when a subdev or SDR are plugged into the host.
An attacker can create an targeted USB device which can emulate 64 of these devices. Then by emulating an additional device which continuously connects and
disconnects, each connection attempt will leak memory which can not be recovered.
Statement: Red Hat
Debian
CVE-2016-5400: linux - Memory leak in the airspy_probe function in drivers/media/usb/airspy/airspy.c in...
vendor_debian·2016·CVSS 4.3
CVE-2016-5400 [MEDIUM] CVE-2016-5400: linux - Memory leak in the airspy_probe function in drivers/media/usb/airspy/airspy.c in...
Memory leak in the airspy_probe function in drivers/media/usb/airspy/airspy.c in the airspy USB driver in the Linux kernel before 4.7 allows local users to cause a denial of service (memory consumption) via a crafted USB device that emulates many VFL_TYPE_SDR or VFL_TYPE_SUBDEV devices and performs many connect and disconnect operations.
Scope: local
bookworm: resolved (fixed in 4.7.2-1)
bullseye: resolved (fixed in 4.7.2-1)
forky: resolved (fixed in 4.7.2-1)
sid: resolved (fixed in 4.7.2-1)
trixie: resolved (fixed in 4.7.2-1)
GHSA
GHSA-m677-x4w4-vj2w: Memory leak in the airspy_probe function in drivers/media/usb/airspy/airspy
ghsa_unreviewed·2022-05-17
CVE-2016-5400 [MEDIUM] CWE-119 GHSA-m677-x4w4-vj2w: Memory leak in the airspy_probe function in drivers/media/usb/airspy/airspy
Memory leak in the airspy_probe function in drivers/media/usb/airspy/airspy.c in the airspy USB driver in the Linux kernel before 4.7 allows local users to cause a denial of service (memory consumption) via a crafted USB device that emulates many VFL_TYPE_SDR or VFL_TYPE_SUBDEV devices and performs many connect and disconnect operations.
OSV
linux-lts-xenial vulnerabilities
osv·2016-08-30·CVSS 5.5
CVE-2016-1237 [MEDIUM] linux-lts-xenial vulnerabilities
linux-lts-xenial vulnerabilities
USN-3070-1 fixed vulnerabilities in the Linux kernel for Ubuntu
16.04 LTS. This update provides the corresponding updates for the
Linux Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for
Ubuntu 14.04 LTS.
A missing permission check when settings ACLs was discovered in nfsd. A
local user could exploit this flaw to gain access to any file by setting an
ACL. (CVE-2016-1237)
Kangjie Lu discovered an information leak in the Reliable Datagram Sockets
(RDS) implementation in the Linux kernel. A local attacker could use this
to obtain potentially sensitive information from kernel memory.
(CVE-2016-5244)
James Patrick-Evans discovered that the airspy USB device driver in the
Linux kernel did not properly handle certain error conditions. An attacker
with
OSV
linux-snapdragon vulnerabilities
osv·2016-08-30·CVSS 5.5
CVE-2016-1237 [MEDIUM] linux-snapdragon vulnerabilities
linux-snapdragon vulnerabilities
A missing permission check when settings ACLs was discovered in nfsd. A
local user could exploit this flaw to gain access to any file by setting an
ACL. (CVE-2016-1237)
Kangjie Lu discovered an information leak in the Reliable Datagram Sockets
(RDS) implementation in the Linux kernel. A local attacker could use this
to obtain potentially sensitive information from kernel memory.
(CVE-2016-5244)
James Patrick-Evans discovered that the airspy USB device driver in the
Linux kernel did not properly handle certain error conditions. An attacker
with physical access could use this to cause a denial of service (memory
consumption). (CVE-2016-5400)
Yue Cao et al discovered a flaw in the TCP implementation's handling of
challenge acks in the Linux kernel. A remot
OSV
linux-raspi2 vulnerabilities
osv·2016-08-30·CVSS 5.5
CVE-2016-1237 [MEDIUM] linux-raspi2 vulnerabilities
linux-raspi2 vulnerabilities
A missing permission check when settings ACLs was discovered in nfsd. A
local user could exploit this flaw to gain access to any file by setting an
ACL. (CVE-2016-1237)
Kangjie Lu discovered an information leak in the Reliable Datagram Sockets
(RDS) implementation in the Linux kernel. A local attacker could use this
to obtain potentially sensitive information from kernel memory.
(CVE-2016-5244)
James Patrick-Evans discovered that the airspy USB device driver in the
Linux kernel did not properly handle certain error conditions. An attacker
with physical access could use this to cause a denial of service (memory
consumption). (CVE-2016-5400)
Yue Cao et al discovered a flaw in the TCP implementation's handling of
challenge acks in the Linux kernel. A remote at
OSV
linux vulnerabilities
osv·2016-08-29·CVSS 5.5
CVE-2016-1237 [MEDIUM] linux vulnerabilities
linux vulnerabilities
A missing permission check when settings ACLs was discovered in nfsd. A
local user could exploit this flaw to gain access to any file by setting an
ACL. (CVE-2016-1237)
Kangjie Lu discovered an information leak in the Reliable Datagram Sockets
(RDS) implementation in the Linux kernel. A local attacker could use this
to obtain potentially sensitive information from kernel memory.
(CVE-2016-5244)
James Patrick-Evans discovered that the airspy USB device driver in the
Linux kernel did not properly handle certain error conditions. An attacker
with physical access could use this to cause a denial of service (memory
consumption). (CVE-2016-5400)
Yue Cao et al discovered a flaw in the TCP implementation's handling of
challenge acks in the Linux kernel. A remote attacker
OSV
CVE-2016-5400: Memory leak in the airspy_probe function in drivers/media/usb/airspy/airspy
osv·2016-08-06·CVSS 4.3
CVE-2016-5400 [MEDIUM] CVE-2016-5400: Memory leak in the airspy_probe function in drivers/media/usb/airspy/airspy
Memory leak in the airspy_probe function in drivers/media/usb/airspy/airspy.c in the airspy USB driver in the Linux kernel before 4.7 allows local users to cause a denial of service (memory consumption) via a crafted USB device that emulates many VFL_TYPE_SDR or VFL_TYPE_SUBDEV devices and performs many connect and disconnect operations.
Kernel
media: fix airspy usb probe error path
kernel_security·2016-07-15·CVSS 4.3
CVE-2016-5400 [MEDIUM] media: fix airspy usb probe error path
media: fix airspy usb probe error path
Fix a memory leak on probe error of the airspy usb device driver.
The problem is triggered when more than 64 usb devices register with
v4l2 of type VFL_TYPE_SDR or VFL_TYPE_SUBDEV.
The memory leak is caused by the probe function of the airspy driver
mishandeling errors and not freeing the corresponding control structures
when an error occours registering the device to v4l2 core.
A badusb device can emulate 64 of these devices, and then through
continual emulated connect/disconnect of the 65th device, cause the
kernel to run out of RAM and crash the kernel, thus causing a local DOS
vulnerability.
Fixes CVE-2016-5400
Signed-off-by: James Patrick-Evans
Reviewed-by: Kees Cook
Cc: [email protected] # 3.17+
Signed-off-by: Linus Torvalds
Kernel
[media] airspy: fix error logic during device register
kernel_security·2016-07-15·CVSS 4.3
CVE-2016-5400 [MEDIUM] [media] airspy: fix error logic during device register
[media] airspy: fix error logic during device register
This patch addresses CVE-2016-5400, a local DOS vulnerability caused by
a memory leak in the airspy usb device driver.
The vulnerability is triggered when more than 64 usb devices register
with v4l2 of type VFL_TYPE_SDR or VFL_TYPE_SUBDEV.A badusb device can
emulate 64 of these devices then through continual emulated
connect/disconnect of the 65th device, cause the kernel to run out of
RAM and crash the kernel.
The vulnerability exists in kernel versions from 3.17 to current 4.7.
The memory leak is caused by the probe function of the airspy driver
mishandeling errors and not freeing the corresponding control structures
when an error occours registering the device to v4l2 core.
Signed-off-by: James Patrick-Evans
Cc: [email protected]
No detection rules found.
No public exploits indexed.
arXiv
What Do They Fix? LLM-Aided Categorization of Security Patches for Critical Memory Bugs
arxiv_fulltext·2025-09-26
What Do They Fix? LLM-Aided Categorization of Security Patches for Critical Memory Bugs
What Do They Fix? LLM-Aided Categorization of Security Patches for Critical Memory Bugs
Xingyu Li ,
Juefei Pu ,
Yifan Wu ,
Xiaochen Zou ,
Shitong Zhu ,
Qiushi Wu ,
Zheng Zhang ,
Joshua Hsu ,\ -0.2ex]
Yue Dong ,
Zhiyun Qian ,
Kangjie Lu ,
Trent Jaeger ,
Michael De Lucia ,
Srikanth V. Krishnamurthy
[ ][c]
\,UC Riverside
\,University of Minnesota
\,IBM
\,U.S.\ Army Research Laboratory
[ ][c]
\,\xli399,jpu007,fshal003,xzou017,szhu014,zzhan173,jhsu094,yued,trentj,zhiyun.qian,krish\@ucr.edu
[ ][c]
\,[email protected]
\,[email protected]
\,[email protected]
## Abstract
Open-source software projects are foundational to modern software ecosystems, with the Linux kernel standing out as a critical exemplar due to its ubiquity and complexity.
Although security patches are continuously i
Bugzilla
CVE-2016-5400 kernel: memory leak in airspy usb driver
bugzilla·2016-07-20·CVSS 4.3
CVE-2016-5400 [MEDIUM] CVE-2016-5400 kernel: memory leak in airspy usb driver
CVE-2016-5400 kernel: memory leak in airspy usb driver
A flaw was found in the linux kernel's implementation of the airspy USB device driver in which a leak was found when a subdev or SDR are plugged into the host.
An attacker can create an targeted USB device which can emulate 64 of
these devices. Then by emulating an additional device which continuously connects and disconnects, each connection attempt will leak memory which can not be recovered.
Upstream patch:
https://git.linuxtv.org/media_tree.git/commit/?id=eca2d34b9d2ce70165a50510659838e28ca22742
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1358186]
---
Statement:
Red Hat Enterprise Linux is not affected by this flaw as this module is not available in shipping source code.
---
Acknowle
Bugzilla
CVE-2016-5400 kernel: memory leak in airspy usb driver [fedora-all]
bugzilla·2016-07-20·CVSS 4.3
CVE-2016-5400 [MEDIUM] CVE-2016-5400 kernel: memory leak in airspy usb driver [fedora-all]
CVE-2016-5400 kernel: memory leak in airspy usb driver [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. Wh
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=aa93d1fee85c890a34f2510a310e55ee76a27848http://www.openwall.com/lists/oss-security/2016/07/25/1http://www.securityfocus.com/bid/92104http://www.securitytracker.com/id/1036432http://www.ubuntu.com/usn/USN-3070-1http://www.ubuntu.com/usn/USN-3070-2http://www.ubuntu.com/usn/USN-3070-3http://www.ubuntu.com/usn/USN-3070-4https://bugzilla.redhat.com/show_bug.cgi?id=1358184https://github.com/torvalds/linux/commit/aa93d1fee85c890a34f2510a310e55ee76a27848http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=aa93d1fee85c890a34f2510a310e55ee76a27848http://www.openwall.com/lists/oss-security/2016/07/25/1http://www.securityfocus.com/bid/92104http://www.securitytracker.com/id/1036432http://www.ubuntu.com/usn/USN-3070-1http://www.ubuntu.com/usn/USN-3070-2http://www.ubuntu.com/usn/USN-3070-3http://www.ubuntu.com/usn/USN-3070-4https://bugzilla.redhat.com/show_bug.cgi?id=1358184https://github.com/torvalds/linux/commit/aa93d1fee85c890a34f2510a310e55ee76a27848
2016-08-06
Published