CVE-2016-2384 describes a double free vulnerability in the Linux kernel's USB MIDI driver (snd_usbmidi_create function) affecting versions prior to 4.5, including various SUSE and Novell Linux distributions. This flaw allows a physically proximate attacker to trigger a denial of service (system panic) or potentially achieve other unspecified impacts by manipulating invalid USB descriptors. Rated Medium severity (CVSS 4.6), it requires physical access and has low attack complexity, with a high impact on availability. While not listed on CISA's KEV, an ExploitDB entry (EDB-41999) exists demonstrating privilege escalation, and it has garnered some community discussion and media coverage, including a Hackernews article mentioning arbitrary code execution.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.4.8CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
12CPE matchmatch criteria | cpe:2.3:o:novell:suse_linux_enterprise_real_time_extension:12:sp1:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.