CVE-2017-16535: High severity android vulnerability
Last updated 29 November 2024
Other sources
The usbgetbosdescriptor function in drivers/usb/core/config.c in the Linux kernel before 4.13.10 allows local users to cause a denial of service (out-of-bounds read and system crash) or possibly have unspecified other impact via a crafted USB device.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-16535?
CVE-2017-16535 is classified as a high severity vulnerability due to its potential to cause a denial of service and system crashes.
How do I fix CVE-2017-16535?
To fix CVE-2017-16535, update your Linux kernel to version 4.13.10 or later.
What systems are affected by CVE-2017-16535?
CVE-2017-16535 affects Linux kernels before version 4.13.10 and certain versions of Google Android.
What is the impact of CVE-2017-16535?
The impact of CVE-2017-16535 includes local users being able to trigger a denial of service through crafted USB devices.
Are there known exploits for CVE-2017-16535?
Yes, there are known exploits that leverage CVE-2017-16535 to cause system crashes or other unspecified impacts.