CVE-2016-4482: Canonical Ubuntu Linux
Medium severity, CVSS 6.2. EPSS: 0.6% chance of exploitation in the next 30 days.
The proc_connectinfo function in drivers/usb/core/devio.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via a crafted USBDEVFS_CONNECTINFO ioctl call.
Affected products
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 15.10 only; version 16.04 only
- Fedoraproject Fedora: version 24 only
- Linux Linux Kernel: up to and including 4.6
- Novell Suse Linux Enterprise Debuginfo: version 11.0 only
- Novell Suse Linux Enterprise Desktop: version 12.0 only
- Novell Suse Linux Enterprise Live Patching: version 12.0 only
- Novell Suse Linux Enterprise Module For Public Cloud: version 12.0 only
- Novell Suse Linux Enterprise Real Time Extension: version 12.0 only
- Novell Suse Linux Enterprise Server: version 11.0 only; version 12.0 only
- Novell Suse Linux Enterprise Software Development Kit: version 11.0 only; version 12.0 only
- Novell Suse Linux Enterprise Workstation Extension: version 12.0 only
Published 2016-05-23. Last modified 2026-06-17.