CVE-2017-16913: Linux Kernel

Medium severity, CVSS 5.9. EPSS: 3.9% chance of exploitation in the next 30 days.

The "stub_recv_cmd_submit()" function (drivers/usb/usbip/stub_rx.c) in the Linux Kernel before version 4.14.8, 4.9.71, and 4.4.114 when handling CMD_SUBMIT packets allows attackers to cause a denial of service (arbitrary memory allocation) via a specially crafted USB over IP packet.

Affected products

  • Linux Linux Kernel: from 4.1.0, before 4.1.49 (fixed in 4.1.49); from 4.4.0, before 4.4.107 (fixed in 4.4.107); from 4.9.0, before 4.9.71 (fixed in 4.9.71); from 4.14.0, before 4.14.8 (fixed in 4.14.8)

Published 2018-01-31. Last modified 2026-06-17.