CVE-2018-16276: High severity Linux Linux kernel vulnerability
An issue was discovered in yurexread in drivers/usb/misc/yurex.c in the Linux kernel before 4.17.7. Local attackers could use user access read/writes with incorrect bounds checking in the yurex USB driver to crash the kernel or potentially escalate privileges.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.176-1Fixed in 6.1.180-1Fixed in 6.12.94-1Fixed in 6.12.107-1Fixed in 7.1.12-1Fixed in 7.1.13-1 - Upgrade
Upgrade
linux kernel (drivers/usb/misc/yurex.c / yurex_read in yurex USB driver)to a version that resolves this vulnerability.Fixed in 4.17.7
Event History
Frequently Asked Questions
What is the severity of CVE-2018-16276?
CVE-2018-16276 is categorized as a high severity vulnerability due to the potential for local privilege escalation and kernel crashes.
How do I fix CVE-2018-16276?
To fix CVE-2018-16276, upgrade your Linux kernel to version 4.17.7 or later.
Which Linux versions are affected by CVE-2018-16276?
CVE-2018-16276 affects Linux kernel versions before 4.17.7, including various versions in the 2.6, 3.x, and 4.x series.
Can CVE-2018-16276 be exploited remotely?
CVE-2018-16276 requires local access to exploit, making it a local attack vector rather than a remote one.
What are the potential impacts of CVE-2018-16276?
The impacts of CVE-2018-16276 include potential kernel crashes and unauthorized privilege escalation for local attackers.