CVE-2016-3951: Double Free
A vulnerability was found in the usbnet Linux kernel driver.
The bug allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have other impact by inserting a USB device with an invalid USB descriptor.
Upstream fixes:
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=4d06dd537f95683aba3651098ae288b7cbff8274 https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=1666984c8625b3db19a9abc298931d35ab7bc64b
External references:
https://www.spinics.net/lists/netdev/msg367669.html https://bugzilla.novell.com/showbug.cgi?id=974418
Reference and CVE assignment:
http://seclists.org/oss-sec/2016/q2/19
Other sources
Double free vulnerability in drivers/net/usb/cdcncm.c in the Linux kernel before 4.5 allows physically proximate attackers to cause a denial of service (system crash) or possibly have unspecified other impact by inserting a USB device with an invalid USB descriptor.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this double free vulnerability?
The vulnerability ID for this double free vulnerability is CVE-2016-3951.
What is the severity of CVE-2016-3951?
The severity of CVE-2016-3951 is low.
How does CVE-2016-3951 affect Linux kernel versions?
CVE-2016-3951 affects Linux kernel versions before 4.5.
What is the impact of CVE-2016-3951?
The impact of CVE-2016-3951 is a denial of service (system crash) or possibly unspecified other impact by inserting a USB device with an invalid USB descriptor.
How can I fix CVE-2016-3951?
To fix CVE-2016-3951, update your Linux kernel to version 4.5 or later.