CVE-2016-5400 describes a memory leak vulnerability in the airspy USB driver within the Linux kernel (before version 4.7). This flaw allows a local attacker, using a specially crafted USB device, to trigger a denial of service by repeatedly connecting and disconnecting the device, leading to excessive memory consumption. Rated as Medium severity (CVSS 4.3), the attack requires physical access to the system and has a high impact on availability, but no impact on confidentiality or integrity. There is no evidence of active exploitation, and public exploit code is unavailable, though it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.6.6CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:P/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.