CVE-2013-1860: Canonical Ubuntu Linux
Medium severity, CVSS 6.9. EPSS: 0.8% chance of exploitation in the next 30 days.
Heap-based buffer overflow in the wdm_in_callback function in drivers/usb/class/cdc-wdm.c in the Linux kernel before 3.8.4 allows physically proximate attackers to cause a denial of service (system crash) or possibly execute arbitrary code via a crafted cdc-wdm USB device.
Affected products
- Canonical Ubuntu Linux: version 10.04 only; version 12.04 only; version 12.10 only
- Linux Linux Kernel: before 3.0.70 (fixed in 3.0.70); from 3.1, before 3.2.41 (fixed in 3.2.41); from 3.3, before 3.4.37 (fixed in 3.4.37); from 3.5, before 3.8.4 (fixed in 3.8.4)
Published 2013-03-22. Last modified 2026-06-16.