CVE-2016-3951: Canonical Ubuntu Linux

Medium severity, CVSS 4.6. EPSS: 0.6% chance of exploitation in the next 30 days.

Double free vulnerability in drivers/net/usb/cdc_ncm.c in the Linux kernel before 4.5 allows physically proximate attackers to cause a denial of service (system crash) or possibly have unspecified other impact by inserting a USB device with an invalid USB descriptor.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 15.10 only
  • Linux Linux Kernel: version 4.5.0 only
  • Novell Suse Linux Enterprise Desktop: version 12 only
  • Novell Suse Linux Enterprise Live Patching: version 12.0 only
  • Novell Suse Linux Enterprise Module For Public Cloud: version 12 only
  • Novell Suse Linux Enterprise Real Time Extension: version 12 only
  • Novell Suse Linux Enterprise Server: version 12.0 only
  • Novell Suse Linux Enterprise Software Development Kit: version 12.0 only
  • Novell Suse Linux Enterprise Workstation Extension: version 12.0 only
  • Suse Suse Linux Enterprise Software Development Kit: version 12.0 only

Published 2016-05-02. Last modified 2026-06-17.