CVE-2016-5829: Canonical Ubuntu Linux
High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.
Multiple heap-based buffer overflows in the hiddev_ioctl_usage function in drivers/hid/usbhid/hiddev.c in the Linux kernel through 4.6.3 allow local users to cause a denial of service or possibly have unspecified other impact via a crafted (1) HIDIOCGUSAGES or (2) HIDIOCSUSAGES ioctl call.
Affected products
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 16.04 only
- Debian Debian Linux: version 8.0 only
- Linux Linux Kernel: before 3.2.82 (fixed in 3.2.82); from 3.3, before 3.10.103 (fixed in 3.10.103); from 3.11, before 3.12.62 (fixed in 3.12.62); from 3.13, before 3.14.74 (fixed in 3.14.74); from 3.15, before 3.16.37 (fixed in 3.16.37); from 3.17, before 3.18.37 (fixed in 3.18.37); …
- Novell Suse Linux Enterprise Real Time Extension: version 12 only
Published 2016-06-27. Last modified 2026-06-17.