CVE-2016-7912: Linux Kernel
High severity, CVSS 7.8. EPSS: 2.1% chance of exploitation in the next 30 days.
Use-after-free vulnerability in the ffs_user_copy_worker function in drivers/usb/gadget/function/f_fs.c in the Linux kernel before 4.5.3 allows local users to gain privileges by accessing an I/O data structure after a certain callback call.
Affected products
- Linux Linux Kernel: from 3.15, before 3.16.40 (fixed in 3.16.40); from 3.17, before 4.1.24 (fixed in 4.1.24); from 4.2, before 4.4.9 (fixed in 4.4.9); from 4.5, before 4.5.3 (fixed in 4.5.3)
Published 2016-11-16. Last modified 2026-06-17.