cbcvebase.
CVE-2018-20961
published 2019-08-07

CVE-2018-20961: In the Linux kernel before 4.16.4, a double free vulnerability in the f_midi_set_alt function of drivers/usb/gadget/function/f_midi.c in the f_midi driver may…

PriorityP340critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
6.34%
92.9th percentile
In the Linux kernel before 4.16.4, a double free vulnerability in the f_midi_set_alt function of drivers/usb/gadget/function/f_midi.c in the f_midi driver may allow attackers to cause a denial of service or possibly have unspecified other impact.

Affected

11 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 4.16.5-1 (bookworm)linux 4.16.5-1 (bookworm)
googleandroid
linuxlinux_kernel>= 0 < 4.16.5-14.16.5-1
linuxlinux_kernel>= 0 < 4.16.5-14.16.5-1
linuxlinux_kernel>= 0 < 4.16.5-14.16.5-1
linuxlinux_kernel>= 0 < 4.16.5-14.16.5-1
linuxlinux_kernel>= 0 < 4.4.0-165.1934.4.0-165.193
linuxlinux_kernel>= 4.10 < 4.14.364.14.36
linuxlinux_kernel>= 4.15.0 < 4.16.44.16.4
linuxlinux_kernel>= 4.4 < 4.4.1904.4.190
linuxlinux_kernel>= 4.5 < 4.9.964.9.96

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.