CVE-2016-7913: Use After Free
Last updated 4 July 2026
Other sources
The xc2028setconfig function in drivers/media/tuners/tuner-xc2028.c in the Linux kernel before 4.6 allows local users to gain privileges or cause a denial of service (use-after-free) via vectors involving omission of the firmware name from a certain data structure.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.176-1Fixed in 6.1.187-1Fixed in 6.12.107-1Fixed in 6.12.111-1Fixed in 7.2.8-1Fixed in 7.2.9-1 - Upgrade
Upgrade
linux kernel (drivers/media/tuners/tuner-xc2028.c)to a version that resolves this vulnerability.Fixed in 4.6 - Compensating control
Mitigate local user attack surface by restricting untrusted users’ access to the affected kernel media/tuner functionality (e.g., limit which users/processes can interact with /dev/media* and related tuner interfaces) since the flaw could enable privilege escalation or denial of service.
Event History
Frequently Asked Questions
What is the severity of CVE-2016-7913?
The severity of CVE-2016-7913 is critical with a severity value of 9.
How can local users exploit CVE-2016-7913?
Local users can gain privileges or cause a denial of service (use-after-free) by exploiting CVE-2016-7913.
What is the affected software of CVE-2016-7913?
The affected software of CVE-2016-7913 includes the Linux kernel before version 4.6.
How can I fix CVE-2016-7913?
To fix CVE-2016-7913, update the Linux kernel to version 4.6 or later.
Where can I find more information about CVE-2016-7913?
You can find more information about CVE-2016-7913 in the references section of the vulnerability report.