cbcvebase.
CVE-2017-16538
published 2017-11-04

CVE-2017-16538: drivers/media/usb/dvb-usb-v2/lmedm04.c in the Linux kernel through 4.13.11 allows local users to cause a denial of service (general protection fault and system…

PriorityP423medium6.6CVSS 3.0
AVPACLPRLUINSUCHIHAH
EPSS
0.40%
32.5th percentile
drivers/media/usb/dvb-usb-v2/lmedm04.c in the Linux kernel through 4.13.11 allows local users to cause a denial of service (general protection fault and system crash) or possibly have unspecified other impact via a crafted USB device, related to a missing warm-start check and incorrect attach timing (dm04_lme2510_frontend_attach versus dm04_lme2510_tuner).

Affected

8 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 4.14.7-1 (bookworm)linux 4.14.7-1 (bookworm)
linuxlinux_kernel<= 4.13.11
linuxlinux_kernel>= 0 < 4.14.7-14.14.7-1
linuxlinux_kernel>= 0 < 4.14.7-14.14.7-1
linuxlinux_kernel>= 0 < 4.14.7-14.14.7-1
linuxlinux_kernel>= 0 < 4.14.7-14.14.7-1
linuxlinux_kernel>= 0 < 3.13.0-157.2073.13.0-157.207
linuxlinux_kernel>= 0 < 4.4.0-121.1454.4.0-121.145

CVSS provenance

nvdv3.06.6MEDIUMCVSS:3.0/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.1HIGH
vendor_ubuntu7.1HIGH
vendor_debian6.6MEDIUM
vendor_redhat6.6MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.