CVE-2017-16911: Linux Kernel

Medium severity, CVSS 4.7. EPSS: 0.4% chance of exploitation in the next 30 days.

The vhci_hcd driver in the Linux Kernel before version 4.14.8 and 4.4.114 allows allows local attackers to disclose kernel memory addresses. Successful exploitation requires that a USB device is attached over IP.

Affected products

  • Linux Linux Kernel: from 4.4.0, before 4.4.114 (fixed in 4.4.114); from 4.9.0, before 4.9.79 (fixed in 4.9.79); from 4.14.0, before 4.14.8 (fixed in 4.14.8)

Published 2018-01-31. Last modified 2026-06-17.