CVE-2017-16528: Use After Free
Published Nov 4, 2017
·Updated
Last updated 29 November 2024
Other sources
sound/core/seqdevice.c in the Linux kernel before 4.13.4 allows local users to cause a denial of service (sndrawmididevseqfree use-after-free and system crash) or possibly have unspecified other impact via a crafted USB device.
Affected Software
8 affected componentsFixes available
Linux Linux kernel>=3.19<4.1.47
Linux Linux kernel>=4.2<4.4.99
Linux Linux kernel>=4.5<4.9.63
Linux Linux kernel>=4.10<4.13.4
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Linux Linux kernel<=4.13.3
debian/linux
5.10.223-15.10.234-16.1.129-16.1.135-16.12.25-1
Remediation
Event History
Nov 4, 2017
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Jan 11, 2024
Data Sourced
via Launchpad·10:32 PM
Description
Dec 1, 2024
Data Sourced
via Ubuntu·01:57 AM
RemedyDescriptionSeverityAffected Software
Mar 27, 2025
Data Sourced
via Debian·03:43 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2017-16528.
2
What is the impact of CVE-2017-16528?
CVE-2017-16528 can allow local users to cause a denial of service or have other unspecified impact.
3
Which versions of the Linux kernel are affected by CVE-2017-16528?
Linux kernel versions before 4.13.4 are affected by CVE-2017-16528.
4
How can I fix CVE-2017-16528?
To fix CVE-2017-16528, update your Linux kernel to version 4.13.4 or later.
5
Where can I find more information about CVE-2017-16528?
You can find more information about CVE-2017-16528 in the references provided.