CVE-2017-16912: Linux Kernel
Medium severity, CVSS 5.9. EPSS: 4.1% chance of exploitation in the next 30 days.
The "get_pipe()" function (drivers/usb/usbip/stub_rx.c) in the Linux Kernel before version 4.14.8, 4.9.71, and 4.4.114 allows attackers to cause a denial of service (out-of-bounds read) via a specially crafted USB over IP packet.
Affected products
- Linux Linux Kernel: from 4.1.0, before 4.1.49 (fixed in 4.1.49); from 4.4.0, up to and including 4.4.107; from 4.9.0, up to and including 4.9.71; from 4.14.0, up to and including 4.14.8
Published 2018-01-31. Last modified 2026-06-17.